<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://yulliwasameur.github.io/feed/publications.xml" rel="self" type="application/atom+xml" /><link href="https://yulliwasameur.github.io/" rel="alternate" type="text/html" /><updated>2026-09-19T19:29:13+02:00</updated><id>https://yulliwasameur.github.io/feed/publications.xml</id><title type="html">Yulliwas AMEUR | Publications</title><subtitle>Dr Yulliwas Ameur, enseignant-chercheur en cybersécurité à Efrei : cryptographie, PPML, sécurité des systèmes, réseaux et IA.</subtitle><author><name>Yulliwas Ameur</name><email>yulliwas.ameur@efrei.fr</email><uri>https://cv.hal.science/yulliwas-ameur</uri></author><entry><title type="html">Context vs. Compute: Self-Hosted Detection Rule Generation with Knowledge-Graph-Augmented Language Models</title><link href="https://yulliwasameur.github.io/publication/2026-09-19-context-vs-compute/" rel="alternate" type="text/html" title="Context vs. Compute: Self-Hosted Detection Rule Generation with Knowledge-Graph-Augmented Language Models" /><published>2026-09-19T00:00:00+02:00</published><updated>2026-09-19T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/context-vs-compute</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-19-context-vs-compute/"><![CDATA[<p><strong>Status:</strong> Accepted for IEEE CloudCom 2026 proceedings with a poster presentation opportunity, subject to registration and camera-ready requirements. Proceedings publication and DOI are not yet verified.</p>

<h2 id="contribution-in-brief">Contribution in brief</h2>

<p>This work compares model capacity and structured context for generating SIEM detection rules. It contrasts no context, retrieval-augmented context, knowledge-graph context and their combination across open-weight models. The evaluation separates structural properties of generated rules from their effectiveness in detecting attacks.</p>

<p>The available submission used cloud inference infrastructure. Equivalence with local quantized deployment was assumed and had not yet been validated in that version. The camera-ready revision is in preparation, so numerical claims should be taken from the eventual final manuscript.</p>

<h2 id="publication-status">Publication status</h2>

<p>The organizers offered proceedings publication with a poster on 15 September 2026. Final publication remains subject to author registration and the conference’s camera-ready requirements. This record does not claim a regular oral presentation, a completed proceedings deposit or an assigned DOI. The page date is the date this record was added.</p>

<p>Related work: <a href="/publication/2026-09-18-knowledge-graph-siem/">LLM4Sec</a> · <a href="/publication/2026-09-18-detection-engineering/">ANUBIS</a>.</p>]]></content><author><name>Tristan Madani</name></author><summary type="html"><![CDATA[Comparing knowledge-graph and retrieval context across open-weight language model capacities for Sigma detection-rule generation.]]></summary></entry><entry><title type="html">From Attack Scenario to Measurable Detection Improvement: A Knowledge-Driven ATT&amp;amp;CK/D3FEND Framework for Instrumented Purple Teaming</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-purple-teaming/" rel="alternate" type="text/html" title="From Attack Scenario to Measurable Detection Improvement: A Knowledge-Driven ATT&amp;amp;CK/D3FEND Framework for Instrumented Purple Teaming" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/purple-teaming</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-purple-teaming/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-11. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="abstract">Abstract</h2>

<p>Organizations run purple team exercises, find gaps, patch a few rules, and report success—but without a formal measurement framework, they cannot quantify how much detection improved or why specific techniques went undetected. Attack prediction models achieve strong F1 scores but produce no defensive output, while CTI knowledge graphs map threats to countermeasures without testing them on real telemetry. The gap between emulating an attack and proving that detection improved remains open. We close this gap with a knowledge-graph-driven framework for instrumented purple teaming. A bidirectional knowledge graph encodes the full chain from ATT&amp;CK technique to data source, detection strategy, analytic rule, log source, and sensor—not just the attack side. Each emulation step is annotated with expected telemetry and success criteria, so that when detection fails, backward traversal of the graph pinpoints why: a missing log source, an absent rule, or an inadequate configuration. After targeted remediation, the same scenario is replayed and improvement is quantified through operational KPIs anchored by detection coverage (𝐶). We evaluate on four threat profiles—nation-state espionage (APT29), financial cybercrime (FIN6), state destructive operations (Sandworm), and big-game-hunting ransomware (Wizard Spider)—all sourced from the public CTID adversary emulation library [1]. The primary endpoint is detection coverage (𝐶), evaluated with a fixed-threshold decision rule (Δ𝐶 &gt; 0.10 in ≥3/4 scenarios). The four-step detection maturity ladder raises strict coverage from 𝐶0 = 23.1% (out-of-the-box SIEM) to 𝐶3 = 71.6% (with KGPT (Knowledge-Graph Purple Teaming)-guided rules), with the KG-guided rule engineering step alone contributing Δ𝐶3 = +30.3 percentage points on average. The decision rule is satisfied in all four scenarios.</p>

<h2 id="available-version">Available version</h2>

<p>Author manuscript, 16 pages, archived on 13 May 2026. The PDF contains the authors’ CC BY 4.0 notice and is shared unchanged. The final proceedings version is not yet verified. Section 10 describes an artifact repository kept private during review; no public implementation is linked here.</p>]]></content><author><name>Tristan Madani</name></author><summary type="html"><![CDATA[Organizations run purple team exercises, find gaps, patch a few rules, and report success—but without a formal measurement framework, they cannot quantify how much detection improved or why specific techniques went undet…]]></summary></entry><entry><title type="html">PQTrust-Agent: Policy-Compiled Post-Quantum Trust Contracts for Web-of-Agents Communications</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-pqtrust-agent/" rel="alternate" type="text/html" title="PQTrust-Agent: Policy-Compiled Post-Quantum Trust Contracts for Web-of-Agents Communications" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/pqtrust-agent</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-pqtrust-agent/"><![CDATA[<p><strong>Status:</strong> Accepted conference paper; proceedings forthcoming.</p>

<p><strong>Conference period:</strong> 2026-12. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="abstract">Abstract</h2>

<p>Autonomous Web agents can agree on a task while enforcing incompatible cryptographic, fallback, resumption, and lease policies. This paper presents PQTrust-Agent, a constraint-first bilateral authorization protocol. Each endpoint compiles private capability and hard-policy constraints into a local safe set; commit–reveal locks the disclosed negotiation inputs; and selection is restricted to the common measured-cost Pareto frontier. The outcome is an RFC-8785-canonical task contract signed by both endpoints with ML-DSA and enforced before real TLS 1.3 and task execution; endpoint TLS authentication remains classical X.509. Infeasibility yields a verifiable subset-minimal conflict certificate and a fail-closed abort, with no weaker retry. In a pre-specified 1,040-observation single-machine campaign, all 480 feasible sessions completed, all 150 infeasible sessions aborted before TLS and task execution, and all 200 author-designed conformance and robustness mutations were rejected with their expected outcomes. Median end-to-end latency was 432.7–537.6 ms; minimax itself took 5.25 ms, with no statistically detected runtime or resource difference from three safe baselines. Three of the four feasible scenarios had singleton frontiers. On the only non-singleton evaluated P0/P3 frontier, minimax coincided with canonical-first-safe and minimum-total-cost in all 1,210 preference conflicts; relative to either endpoint’s unilateral minimum-cost selector, it reduced maximum regret in 605 conflicts and tied in 605. Distinct minimax decisions relative to those two safe heuristics appeared only in an explicitly post-hoc constructed 15-profile frontier, while no profitable unilateral misreport was observed on the tested finite grid. These results support an auditable task-scoped fail-closed mechanism, not complete post-quantum endpoint authentication or Internet-scale performance.</p>

<h2 id="open-manuscript">Open manuscript</h2>

<p>The PDF is an author manuscript, with an IEEE copyright and version notice. The version of record will be linked when its DOI is available.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Autonomous Web agents can agree on a task while enforcing incompatible cryptographic, fallback, resumption, and lease policies. This paper presents PQTrust-Agent, a constraint-first bilateral authorization protocol. Each…]]></summary></entry><entry><title type="html">Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-knowledge-graph-siem/" rel="alternate" type="text/html" title="Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/knowledge-graph-siem</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-knowledge-graph-siem/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-09. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="contribution-in-brief">Contribution in brief</h2>

<p>The study uses a knowledge graph to supply valid fields, log sources and Sigma categories to a language model that generates detection rules. It evaluates structural dimensions separately: syntax and compilation, fields, log source, ATT&amp;CK tags and agreement with reference rules.</p>

<p>The revised presentation distinguishes cloud-hosted inference from the possibility of a future self-hosted deployment. It also distinguishes structural agreement from operational detection effectiveness. The reference rules share provenance with the graph and the evaluation scenarios, so agreement with those rules does not provide an independent test of generalization.</p>

<p>This English summary is based on the authors’ revised LLM4Sec presentation dated 14 September 2026, prepared for ESORICS on 18 September. A permanent public URL for the presentation and the artifact has not yet been verified. It should be read alongside the final proceedings version when available.</p>

<p>Related methodology: <a href="/publication/2026-09-18-detection-engineering/">Benchmarking Detection Engineering Improvements through Instrumented Adversary Emulation</a>.</p>]]></content><author><name>Tristan Madani</name></author><summary type="html"><![CDATA[Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules. Conference contribution listed in HAL; proceedings publication details are not yet verified.]]></summary></entry><entry><title type="html">Building a Community-Grounded Spell Checker for the Kabyle Language Using NLP Powered by AI</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-kabyle-spell-checker/" rel="alternate" type="text/html" title="Building a Community-Grounded Spell Checker for the Kabyle Language Using NLP Powered by AI" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/kabyle-spell-checker</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-kabyle-spell-checker/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-11. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="research-summary">Research summary</h2>

<p>This early extended abstract presents a Kabyle spell checker combining edit distance, phonetic matching, n-gram context models and linguistic rules for the state of annexation. It describes community participation and an evaluation using synthetic spelling noise. Evaluation on real errors from OCR and automatic speech recognition is identified as ongoing work; LLM integration is future work in this version.</p>

<h2 id="available-version">Available version</h2>

<p>Early author extended abstract, 3 pages, archived on 18 August 2026. This is the available initial version, not a verified final conference manuscript. The title is retained exactly as in the manuscript and HAL record. The PDF is shared unchanged, including its limitations and AI-use statement. A subsequent conference revision has not been verified.</p>]]></content><author><name>Massil Aoudj</name></author><summary type="html"><![CDATA[Building a Community-Grounded Spell Checker for the Kabyle Language Using NLP Powered by AI. Conference contribution listed in HAL; proceedings publication details are not yet verified.]]></summary></entry><entry><title type="html">GovSecLLM++: A Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-govsecllm-paper/" rel="alternate" type="text/html" title="GovSecLLM++: A Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/govsecllm-paper</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-govsecllm-paper/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-09. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="contribution-in-brief">Contribution in brief</h2>

<p>GovSecLLM++ connects security testing of LLM applications to inspectable governance evidence. Its public artifact package includes adaptive test outputs, scoring utilities, strict rescoring files, human-validation summaries, a data card and reproducibility notes. The examples use synthetic secrets and credentials.</p>

<p>The software and dataset are separately citable objects. <a href="https://doi.org/10.5281/zenodo.20636767">Software DOI</a> · <a href="https://doi.org/10.5281/zenodo.20646701">Dataset concept DOI</a> · <a href="https://doi.org/10.5281/zenodo.20646702">Dataset version DOI</a>. The current code release does not include the final paper PDF.</p>

<p><a href="/research-highlights/">Research highlights and scope of the evidence</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[GovSecLLM++: A Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications. Conference contribution listed in HAL; proceedings publication details are not yet verified.]]></summary></entry><entry><title type="html">Benchmarking Detection Engineering Improvements through Instrumented Adversary Emulation</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-detection-engineering/" rel="alternate" type="text/html" title="Benchmarking Detection Engineering Improvements through Instrumented Adversary Emulation" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/detection-engineering</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-detection-engineering/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-09. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="contribution-in-brief">Contribution in brief</h2>

<p>This study distinguishes an alert that fires from an alert that correctly identifies the emulated ATT&amp;CK technique. Its four outcomes are <strong>det</strong> (correct detection), <strong>det</strong>* (an alert with an incorrect technique mapping), <strong>tel</strong> (telemetry without an alert) and <strong>none</strong> (missing telemetry). The mapping-quality gap is the difference between effective coverage and strict coverage.</p>

<p>The revised presentation describes four scenarios and 80 laboratory runs. Adding 2,396 community rules increases effective coverage by 33.1 percentage points while adding no strict detections in those scenarios. Knowledge-graph diagnosis then guides targeted rule authoring. These targeted rules were evaluated on the same scenarios that informed their design; validation on held-out scenarios remains future work.</p>

<p>This English summary is based on the authors’ revised ANUBIS presentation dated 14 September 2026, prepared for ESORICS on 18 September. A permanent public URL for the presentation and the artifact has not yet been verified. The presentation is a separate object from the final proceedings paper.</p>

<p>Related study: <a href="/publication/2026-09-18-knowledge-graph-siem/">Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules</a>.</p>]]></content><author><name>Tristan Madani</name></author><summary type="html"><![CDATA[Benchmarking Detection Engineering Improvements through Instrumented Adversary Emulation. Conference contribution listed in HAL; proceedings publication details are not yet verified.]]></summary></entry><entry><title type="html">CIGMA: An Evidence-Grounded Cryptographic Inventory Graph for Reproducible Post-Quantum Migration Prioritization</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-cigma/" rel="alternate" type="text/html" title="CIGMA: An Evidence-Grounded Cryptographic Inventory Graph for Reproducible Post-Quantum Migration Prioritization" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/cigma</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-cigma/"><![CDATA[<p><strong>Status:</strong> Conference contribution listed in HAL; proceedings publication details are not yet verified.</p>

<p><strong>Conference period:</strong> 2026-11. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="research-code">Research code</h2>

<p>The archived source snapshot includes the original Python implementation, configuration, synthetic fixture, tests and results. On 18 September 2026, 33 of the 34 existing tests passed. One paper-macro export consistency check failed. See the <a href="/files/cigma-validation.md">validation report</a> before reusing the archived numerical results. The accompanying manuscript is not included in this snapshot.</p>

<p><a href="/files/cigma-artifact-snapshot-2026-08-19.zip">Download the same archived package as ZIP</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[CIGMA: An Evidence-Grounded Cryptographic Inventory Graph for Reproducible Post-Quantum Migration Prioritization. Conference contribution listed in HAL; proceedings publication details are not yet verified.]]></summary></entry><entry><title type="html">AgentFlowShield: Defending LLM Agents Against Metadata Side Channels</title><link href="https://yulliwasameur.github.io/publication/2026-09-18-agentflowshield/" rel="alternate" type="text/html" title="AgentFlowShield: Defending LLM Agents Against Metadata Side Channels" /><published>2026-09-18T00:00:00+02:00</published><updated>2026-09-18T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/agentflowshield</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-09-18-agentflowshield/"><![CDATA[<p><strong>Status:</strong> Accepted conference paper; proceedings forthcoming.</p>

<p><strong>Conference period:</strong> 2026-10. The page date records this listing; it is not a proceedings publication date.</p>

<h2 id="abstract">Abstract</h2>

<p>Tool-augmented LLM agents produce structured, multi-phase network traffic whose encrypted metadata—packet sizes, inter-arrival times, burst boundaries, and streaming cadence—can reveal which tools were invoked, whether retrieval or memory was used, and coarse properties of the underlying task. We study this leakage in a scoped single-endpoint deployment model and introduce AgentFlowShield, a phase-aware egress shaping layer combining bucket padding, frame aggregation, bounded jitter, tool normalisation, memory envelopes, and a risk-aware controller. On a 6,300-trace controlled testbed we evaluate six inference attacks under no-defence, generic, and phase-aware defences, probe generalisation with a template-disjoint split, and evaluate three defence-aware adversaries. We provide a bounded within-phase size-channel analysis, identify residual leakage channels, and demonstrate the defence architecture in a controlled loopback testbed with synthetic WAN noise. AgentFlowShield-full preserves low engineering overhead (24 % measured latency overhead in the final utility run) but does not eliminate leakage against the strongest standard-split adversaries (97-100% residual AUPRC on A1-A4). Its clearest gains appear in the template-disjoint and policy-aware settings: D9 shows mixed results in unseen-template splits, with workflow-type AUPRC increasing from 0.385 to 0.453 (indicating higher detectability) and tool-type decreasing from 0.512 to 0.490, while policy-aware A1 fusion drops from 0.995 under random padding to 0.442 under D9. The final results therefore show a narrower but more defensible claim: phase-aware shaping helps generalisation-resistant and calibrated attacks, but fixed-envelope defences still leave strong residual standard-split signals.</p>

<h2 id="open-manuscript">Open manuscript</h2>

<p>The PDF is an author manuscript, with an IEEE copyright and version notice. The version of record will be linked when its DOI is available.</p>

<h2 id="presentation">Presentation</h2>

<p><a href="/publication/2026-09-18-agentflowshield/slides.pptx">Download the authors’ AgentFlowShield presentation (PowerPoint, 12 slides)</a>.</p>

<p>This is the supplied presentation associated with AICCSA 2026. For exact evaluation conditions, residual leakage and the scope of the results, consult the author manuscript above.</p>

<p><a href="/research-highlights/">English contribution summary</a>.</p>]]></content><author><name>Redha Boukhari</name></author><summary type="html"><![CDATA[Tool-augmented LLM agents produce structured, multi-phase network traffic whose encrypted metadata—packet sizes, inter-arrival times, burst boundaries, and streaming cadence—can reveal which tools were invoked, whether r…]]></summary></entry><entry><title type="html">ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact)</title><link href="https://yulliwasameur.github.io/publication/2026-08-28-software-errorcaps/" rel="alternate" type="text/html" title="ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact)" /><published>2026-08-28T00:00:00+02:00</published><updated>2026-08-28T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/software-errorcaps</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-08-28-software-errorcaps/"><![CDATA[<h2 id="software-archive">Software archive</h2>

<p><strong>Version:</strong> v3.0.1. <strong>Published:</strong> 28 August 2026. <strong>Software license:</strong> MIT, as stated in the <a href="https://zenodo.org/records/22147247">Zenodo record</a>.</p>

<p>The archive describes a synthetic benchmark for indirect prompt injection during error recovery in tool-using agents. Its design combines typed error terminals, a planner that only proposes actions, and a monitor controlling the authority to produce individual effects. It includes per-episode records across seven models, an automated policy-aware attacker, and a comparison between value-based and provenance-based policies. The benchmark uses synthetic canaries; the archive does not report attacks against real systems.</p>

<h2 id="materials-and-reproduction-instructions">Materials and reproduction instructions</h2>

<p>The archive provides the software, recorded results and an offline <code class="language-plaintext highlighter-rouge">make reproduce</code> workflow. Download <code class="language-plaintext highlighter-rouge">errorcaps-repro-v3.0.1.zip</code> from the <a href="https://zenodo.org/records/22147247">official archive for the instructions and recorded results</a>.</p>

<h2 id="associated-manuscript">Associated manuscript</h2>

<p><em>Where Does Recovery-Path Injection Security Come From? Decomposing Error Sanitization, Effect Monitoring, and Policy Precision</em></p>

<p>The archive carries a CRiSIS 2026 label. This label does not establish acceptance or proceedings publication of the associated manuscript. The DOI on this page identifies the software archive, not a journal or proceedings paper.</p>

<h2 id="cite-the-version-used">Cite the version used</h2>

<p>Yulliwas Ameur; Samia Bouzefrane; Soumya Banerjee. ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact). Version v3.0.1. Zenodo, 2026. <a href="https://doi.org/10.5281/zenodo.22147247">Version DOI</a>.</p>

<p>The <a href="https://doi.org/10.5281/zenodo.22146809">concept DOI</a> groups versions of the archive. Cite the version DOI above when using this specific release. <a href="/files/publications.bib">Download the site bibliography in BibTeX</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Versioned software archive for a synthetic benchmark of indirect prompt injection during error recovery in tool-using agents.]]></summary></entry><entry><title type="html">Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact)</title><link href="https://yulliwasameur.github.io/publication/bearer-bound-attested-software/" rel="alternate" type="text/html" title="Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact)" /><published>2026-08-28T00:00:00+02:00</published><updated>2026-08-28T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/software-bearer-bound-attested</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/bearer-bound-attested-software/"><![CDATA[<h2 id="software-archive">Software archive</h2>

<p><strong>Version:</strong> v1.1. <strong>Published:</strong> 28 August 2026. <strong>Software license:</strong> MIT, as stated in the <a href="https://zenodo.org/records/22146879">Zenodo record</a>.</p>

<p>The archive compares four enforcement configurations: bearer JWTs, certificate-bound tokens using RFC 8705, an attestation-gated bound-token control, and SPIFFE X.509 SVIDs. The described architecture combines an NGINX-style policy enforcement point with Open Policy Agent.</p>

<h2 id="materials-and-reproduction-instructions">Materials and reproduction instructions</h2>

<p>The package includes a measurement harness, bootstrap and TOST analysis, ablations and second-host experiments, a ProVerif 2.05 model suite with replay, forwarding and self-assertion controls, and SPIRE 1.9.6 validation material. Download <code class="language-plaintext highlighter-rouge">LNET_V3_artifact.zip</code> from the <a href="https://zenodo.org/records/22146879">official archive for the reproduction instructions and recorded results</a>.</p>

<h2 id="associated-manuscript">Associated manuscript</h2>

<p><em>Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement</em></p>

<p>The archive describes the associated manuscript as a submission to IEEE Networking Letters. Acceptance and publication of the manuscript are not established by this software release. The DOI on this page identifies the software archive, not a journal or proceedings paper.</p>

<h2 id="cite-the-version-used">Cite the version used</h2>

<p>Yulliwas Ameur; Soumya Banerjee; Samia Bouzefrane. Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact). Version v1.1. Zenodo, 2026. <a href="https://doi.org/10.5281/zenodo.22146879">Version DOI</a>.</p>

<p>The <a href="https://doi.org/10.5281/zenodo.22142867">concept DOI</a> groups versions of the archive. Cite the version DOI above when using this specific release. <a href="/files/publications.bib">Download the site bibliography in BibTeX</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Versioned software archive comparing token key binding, provenance and attestation mechanisms for Zero Trust enforcement.]]></summary></entry><entry><title type="html">Energy-Efficient Adaptive Zero Trust Security for Automotive CAN Networks</title><link href="https://yulliwasameur.github.io/publication/2026-07-22-ficloud-zero-trust-can" rel="alternate" type="text/html" title="Energy-Efficient Adaptive Zero Trust Security for Automotive CAN Networks" /><published>2026-07-22T00:00:00+02:00</published><updated>2026-07-22T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/ficloud-zero-trust-can</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-07-22-ficloud-zero-trust-can"><![CDATA[]]></content><author><name>Aditi Kalgi</name></author><summary type="html"><![CDATA[Adaptive Zero Trust security for automotive CAN networks with an emphasis on energy efficiency.]]></summary></entry><entry><title type="html">GovSecLLM++: Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications</title><link href="https://yulliwasameur.github.io/publication/2026-06-11-software-govsecllm" rel="alternate" type="text/html" title="GovSecLLM++: Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications" /><published>2026-06-11T00:00:00+02:00</published><updated>2026-06-11T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/software-govsecllm</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-06-11-software-govsecllm"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Reproducibility package and benchmark for compliance-aware security testing of LLM-based applications.]]></summary></entry><entry><title type="html">GovSecLLM++ SECAI 2026 Artifact Package (dataset)</title><link href="https://yulliwasameur.github.io/publication/2026-06-11-dataset-govsecllm" rel="alternate" type="text/html" title="GovSecLLM++ SECAI 2026 Artifact Package (dataset)" /><published>2026-06-11T00:00:00+02:00</published><updated>2026-06-11T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/dataset-govsecllm</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-06-11-dataset-govsecllm"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>This artifact package accompanies the SECAI 2026 submission: <strong>GovSecLLM++: A Compliance-Aware Benchmark for Security Testing and Governance Evidence in LLM-Based Applications</strong> GovSecLLM++ is a compliance-aware benchmark and evaluation protocol for security testing of LLM-based applications. The benchmark maps governance requirements to application-level risks, adversarial scenario cards, expected safe behaviours, measurable security and governance metrics, and audit evidence. This package contains the experimental artifacts without the final paper source/PDF. It includes: - AdaptiveGovSec-120 outputs and summaries; - corrected F2 hidden-context confidentiality rerun outputs; - mini multi-model benchmark outputs; - strict rescoring files; - human-validation summary workbook; - scoring utilities; - reproducibility notes; - data card; - checksums and package manifest. The main experimental components are: 1. Controlled validation with 6300 runs. 2. Hosted Groq full-suite evaluation with 1050 real-backend runs. 3. Multi-model mini-benchmark and strict rescoring. 4. Corrected F2 rerun to separate hidden-context leakage from user-provided canary echoing. 5. AdaptiveGovSec-120 with 478 successful calls out of 480 expected calls. 6. Human-confirmed validation on a stratified sample of 50 outputs. All secrets, policy records, documents, tools, and credentials are synthetic. The artifact does not contain real personal data, real credentials, or real confidential organizational data. The benchmark provides technical and governance-oriented evaluation evidence. It does not constitute legal certification of compliance with the EU AI Act, ISO/IEC 42001, or any other regulatory framework.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Experimental artifacts of GovSecLLM++, a compliance-aware benchmark for security testing and governance evidence in LLM-based applications.]]></summary></entry><entry><title type="html">Secure k-means Clustering using Homomorphic Encryption</title><link href="https://yulliwasameur.github.io/publication/2026-04-16-ant2026-secure-kmeans" rel="alternate" type="text/html" title="Secure k-means Clustering using Homomorphic Encryption" /><published>2026-04-16T00:00:00+02:00</published><updated>2026-04-16T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/ant2026-secure-kmeans</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-04-16-ant2026-secure-kmeans"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Machine Learning as a Service (MLaaS) enables users to outsource compute-intensive analytics, but processing sensitive data in clear on a cloud server raises strong privacy concerns. Fully Homomorphic Encryption (FHE) enables computations over encrypted data, yet implementing k-means under FHE is challenging because the assignment step requires repeated comparisons (argmin), while centroid updates involve divisions. We propose a TFHE-based privacy-preserving k-means protocol that performs the entire assignment step homomorphically. For each iteration, the cloud evaluates encrypted comparisons of squared Euclidean distance differences using TFHE programmable bootstrapping, and returns encrypted one-hot assignment vectors. The client decrypts only these assignment vectors once per iteration to update centroids in clear and sends the refreshed centroids back. This design eliminates any server-side decryption and avoids trusted third parties while keeping client work lightweight. We evaluate on several real datasets using ARI/NMI (when labels exist) and internal metrics (inertia/silhouette). The encrypted clustering closely matches plaintext Forgy k-means for moderate numbers of clusters, while runtime is dominated by bootstrapping operations and thus benefits from parallelization.</p>]]></content><author><name>Rezak Aziz</name></author><summary type="html"><![CDATA[Privacy-preserving k-means clustering on homomorphically encrypted data using TFHE.]]></summary></entry><entry><title type="html">Artificial Intelligence and Machine Learning: Revolutionizing Supply Chain Security</title><link href="https://yulliwasameur.github.io/publication/2026-01-31-chapter-ai-ml-supply-chain" rel="alternate" type="text/html" title="Artificial Intelligence and Machine Learning: Revolutionizing Supply Chain Security" /><published>2026-01-31T00:00:00+01:00</published><updated>2026-01-31T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/chapter-ai-ml-supply-chain</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2026-01-31-chapter-ai-ml-supply-chain"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[How AI/ML enable predictive analytics, anomaly detection and real-time decision-making for supply chain security.]]></summary></entry><entry><title type="html">Advancing Blockchain Privacy: The Role of Homomorphic Encryption</title><link href="https://yulliwasameur.github.io/publication/2025-06-01-chapter-blockchain-privacy" rel="alternate" type="text/html" title="Advancing Blockchain Privacy: The Role of Homomorphic Encryption" /><published>2025-02-20T00:00:00+01:00</published><updated>2025-02-20T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/chapter-blockchain-privacy</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2025-06-01-chapter-blockchain-privacy"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Homomorphic encryption as a building block for privacy-preserving blockchain applications.]]></summary></entry><entry><title type="html">Developing Adaptive Homomorphic Encryption through Exploration of Differential Privacy</title><link href="https://yulliwasameur.github.io/publication/2024-07-01-jcsm-adaptive-he-dp" rel="alternate" type="text/html" title="Developing Adaptive Homomorphic Encryption through Exploration of Differential Privacy" /><published>2024-09-03T00:00:00+02:00</published><updated>2024-09-03T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/jcsm-adaptive-he-dp</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2024-07-01-jcsm-adaptive-he-dp"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Machine Learning (ML) classifiers are pivotal in various applied ML domains. The accuracy of these classifiers requires meticulous training, making the exposure of training datasets a critical concern, especially concerning privacy. This study identifies a significant trade-off between accuracy, computational efficiency, and security of the classifiers. Integrating classical Homomorphic Encryption (HE) and Differential Privacy (DP) highlights the challenges in parameter tuning inherent to such hybrid methodologies. These challenges concern the analytical components of the HE algorithm’s privacy budget and simultaneously affect the sensitivity to noise in the subjected ML hybrid classifiers. This paper explores these areas and proposes a hybrid model using a basic client-server architecture to combine HE and DP algorithms. It then examines the sensitivity analysis of the aforementioned trade-off features. Additionally, the paper outlines initial observations after deploying the proposed algorithm, contributing to the ongoing discourse on optimizing the balance between accuracy, computational efficiency, and security in ML classifiers.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Combining homomorphic encryption with differential privacy for adaptive privacy-preserving machine learning.]]></summary></entry><entry><title type="html">Peer Review Report: Applications of Homomorphic Encryption in Secure Computation</title><link href="https://yulliwasameur.github.io/publication/2024-08-24-open-research-europe-peer-review" rel="alternate" type="text/html" title="Peer Review Report: Applications of Homomorphic Encryption in Secure Computation" /><published>2024-08-24T00:00:00+02:00</published><updated>2024-08-24T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/open-research-europe-peer-review</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2024-08-24-open-research-europe-peer-review"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Open peer-review report, listed separately from authored research publications.]]></summary></entry><entry><title type="html">Enhancing privacy in VANETs through homomorphic encryption in machine learning applications</title><link href="https://yulliwasameur.github.io/publication/2024-04-25-ant2024-vanets" rel="alternate" type="text/html" title="Enhancing privacy in VANETs through homomorphic encryption in machine learning applications" /><published>2024-04-25T00:00:00+02:00</published><updated>2024-04-25T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/ant2024-vanets</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2024-04-25-ant2024-vanets"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>This paper presents a novel framework for enhancing privacy in Vehicular Ad Hoc Networks (VANETs) by integrating homomorphic encryption with machine learning applications. VANETs, essential for Intelligent Transport Systems (ITS), face significant challenges in privacy and security due to their highly dynamic and heterogeneous nature. Our framework addresses these challenges by employing a simplified but effective machine learning algorithm, the K-nearest neighbors (KNN), to ensure the security and privacy of the network. The flexibility of the framework allows for the incorporation of other machine learning algorithms, enhancing its adaptability and efficiency in various VANET scenarios. Key to this framework is the use of homomorphic encryption (HE), a cryptographic technique that enables computations on encrypted data without the need for decryption. This feature preserves data confidentiality and allows for secure third-party computations. Our paper discusses the evolution and types of homomorphic encryption, emphasizing the importance of Fully Homomorphic Encryption (FHE) for its ability to evaluate complex polynomial functions. The paper also highlights the different domains of cybersecurity concerns in VANETs, including in-vehicle systems, ad-hoc and infrastructure networks, and data analysis. The proposed framework aims to mitigate these vulnerabilities, particularly focusing on preventing common attacks like DoS and location tracking. A significant advantage of our approach is its general nature, making it applicable to various privacy issues in VANETs. We propose the potential integration of homomorphic encryption with other privacy-preserving techniques, such as differential privacy or secure multi-party computation, to enhance computation times while ensuring robust privacy protection.</p>

<h2 id="research-index">Research index</h2>

<p><a href="https://trid.trb.org/View/2421479">TRID — Transportation Research Board record</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Privacy-preserving machine learning for vehicular ad-hoc networks using homomorphic encryption.]]></summary></entry><entry><title type="html">Exploring the Scope of Machine Learning using Homomorphic Encryption in IoT/Cloud (PhD thesis)</title><link href="https://yulliwasameur.github.io/publication/2023-12-18-phd-thesis" rel="alternate" type="text/html" title="Exploring the Scope of Machine Learning using Homomorphic Encryption in IoT/Cloud (PhD thesis)" /><published>2023-12-18T00:00:00+01:00</published><updated>2023-12-18T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/phd-thesis</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2023-12-18-phd-thesis"><![CDATA[<h2 id="abstract-english">Abstract (English)</h2>

<p>Machine Learning as a Service (MLaaS) has accelerated the adoption of machine learning techniques in various fields. However, this trend has also raised serious concerns about the security and privacy of the sensitive data used in machine learning models. To address this challenge, we use homomorphic encryption. The aim of this thesis is to investigate the implementation of homomorphic encryption in different machine learning applications. The first part of the thesis focuses on the use of homomorphic encryption in a multi-cloud environment, where the encryption is applied to simple operations such as addition and multiplication. This thesis investigates the application of homomorphic encryption to the k-nearest neighbors (k-NN) algorithm. The study presents a practical implementation of the k-NN algorithm using homomorphic encryption and demonstrates the feasibility of this approach on a variety of datasets. The results show that the performance of the k-NN algorithm with homomorphic encryption is comparable to that of the unencrypted algorithm. Third, the paper investigates the application of homomorphic encryption to k-means clustering algorithm. Similar to the k-NN study, this paper presents a practical implementation of the k-means algorithm using homomorphic encryption and evaluates its performance using different datasets. Finally, the thesis explores the combination of homomorphic encryption with Differential Privacy (DP) techniques to further improve the confidentiality of machine learning models. The study proposes a novel approach that combines homomorphic encryption with DP to achieve better privacy guarantees for machine learning models. The research results presented in this paper contribute to the growing body of research at the intersection of homomorphic encryption and machine learning and provide practical implementations and evaluations of homomorphic encryption in various machine learning contexts.</p>

<p>Original English abstract from the archived thesis (p. 22). <a href="https://theses.hal.science/tel-04587371">Institutional thesis record and available version on HAL</a>.</p>

<h2 id="résumé-français">Résumé (français)</h2>

<p>Exploration de l’apprentissage automatique avec le chiffrement homomorphe dans l’internet des objets/Cloud L’apprentissage automatique en tant que service (MLaaS) a accéléré l’adoption des techniques d’apprentissage automatique dans divers domaines. Toutefois, cette tendance a également soulevé de sérieuses inquiétudes quant à la sécurité et à la confidentialité des données sensibles utilisées dans les modèles d’apprentissage automatique. Pour relever ce défi, notre approche consiste à utiliser le chiffrement homomorphique.Cette thèse explore l’application du chiffrement homomorphe dans divers contextes d’apprentissage automatique. La première partie du travail se concentre sur l’utilisation du chiffrement homomorphe dans un environnement multi-cloud, où le chiffrement est appliqué à des opérations simples telles que l’addition et la multiplication.Cette thèse explore l’application du chiffrement homomorphique à l’algorithme k-nearest neighbors (k-NN). L’étude présente une implémentation pratique de l’algorithme k-NN utilisant le cryptage homomorphique et démontre la faisabilité de cette approche sur une variété d’ensembles de données. Les résultats montrent que les performances de l’algorithme k-NN utilisant le cryptage homomorphique sont comparables à celles de l’algorithme non chiffré.Troisièmement, les travaux étudient l’application du chiffrement homomorphique à l’algorithme de regroupement k-means. Comme pour l’étude k-NN, la thèse présente une implémentation pratique de l’algorithme k-means utilisant le chiffrement homomorphique et évalue ses performances sur différents ensembles de données.Enfin, la thèse explore la combinaison du chiffrement homomorphique avec des techniques de confidentialité différentielle (DP) pour améliorer encore la confidentialité des modèles d’apprentissage automatique. L’étude propose une nouvelle approche qui combine le chiffrement homomorphique avec la protection différentielle afin d’obtenir de meilleures garanties de confidentialité pour les modèles d’apprentissage automatique. La recherche présentée dans cette thèse contribue au corpus croissant de recherche sur l’intersection du chiffrement homomorphique et de l’apprentissage automatique, en fournissant des implémentations pratiques et des évaluations du chiffrement homomorphique dans divers contextes d’apprentissage automatique.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[PhD thesis supervised by Samia Bouzefrane and Vincent Audigier - privacy-preserving ML (k-NN, k-means, differential privacy) over encrypted data in IoT/Cloud.]]></summary></entry><entry><title type="html">Handling security issues by using homomorphic encryption in multi-cloud environment</title><link href="https://yulliwasameur.github.io/publication/2023-03-15-ant2023-multicloud" rel="alternate" type="text/html" title="Handling security issues by using homomorphic encryption in multi-cloud environment" /><published>2023-03-15T00:00:00+01:00</published><updated>2023-03-15T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/ant2023-multicloud</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2023-03-15-ant2023-multicloud"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Taking advantage of the high performance and powerful data processing capabilities of cloud computing technology, externalizing data to the cloud platform is considered as an inevitable trend in the digital field today. However, ensuring the security and privacy of data remains a major challenge. To overcome this drawback, a multi-cloud platform is proposed to improve privacy and high availability of data. A multi-cloud platform that integrates public, private, and managed clouds with a single user interface. Cloud-hosted data is distributed among different data centers in a multi-cloud environment based on cloud reliability and data sensitivity. In terms of security, current encryption algorithms are considered to be very efficient, but it requires a lot of resources to handle this, which is expensive and time consuming. In addition, they also make the data impossible to process without first decoding. To be specific, traditional public key encryption requires data to be decrypted before it can be analyzed or manipulated. In contrast, homomorphic encryption is an encryption method that allows data to be encrypted while it is being processed and manipulated. It allows user or a third party, which can be cloud provider, to apply functions on encrypted data without revealing the data’s values. In this paper, we explore existing multi-cloud-based security solutions using homomorphic encryption to identify open issues and opportunities for further enhancement.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Securing outsourced computation across multiple cloud providers with homomorphic encryption.]]></summary></entry><entry><title type="html">State-of-the-Art and Development of Privacy-Enhancing Technologies</title><link href="https://yulliwasameur.github.io/publication/2023-03-02-easychair-pets" rel="alternate" type="text/html" title="State-of-the-Art and Development of Privacy-Enhancing Technologies" /><published>2023-03-02T00:00:00+01:00</published><updated>2023-03-02T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/easychair-pets</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2023-03-02-easychair-pets"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Privacy-Enhancing Technologies (PETs) have been developed to securely process and confidently share sensitive data. The two main categories of PETs are those that focus on input privacy and those that focus on output privacy.</p>

<p>Input privacy concerns how parties can manipulate data to prevent it from being used outside of a defined context, while output privacy focuses on modifying calculation results so that output data cannot be used to trace back to original inputs. In this document, we will provide an introduction and overview of PETs by exploring various approaches in the literature. We will conclude this document by discussing the challenges in the adoption of these privacy-preserving technologies.</p>

<p>Our aim throughout this paper is to provide a comprehensive understanding of PETs, their application, and the hurdles that must be overcome for widespread adoption. The implementation of Privacy-Enhancing Technologies (PETs) enables the creation of secure data life cycles, promoting collaboration, trust, and security among those with a stake in the data.</p>

<p>Author abstract reproduced from <a href="https://easychair.org/publications/preprint/j5kR">EasyChair Preprint 9814</a>, published 2 March 2023. <a href="https://easychair.org/publications/preprint/j5kR/open">Read the preprint PDF</a>.</p>]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[A survey of privacy-enhancing technologies and their development for secure data processing.]]></summary></entry><entry><title type="html">Application of Homomorphic Encryption in Machine Learning</title><link href="https://yulliwasameur.github.io/publication/2023-01-01-chapter-he-ml" rel="alternate" type="text/html" title="Application of Homomorphic Encryption in Machine Learning" /><published>2023-01-01T00:00:00+01:00</published><updated>2023-01-01T00:00:00+01:00</updated><id>https://yulliwasameur.github.io/publication/chapter-he-ml</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2023-01-01-chapter-he-ml"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[Survey and practical perspective on homomorphic encryption schemes and tools for privacy-preserving machine learning.]]></summary></entry><entry><title type="html">Secure and non-interactive k-NN classifier using symmetric fully homomorphic encryption</title><link href="https://yulliwasameur.github.io/publication/2022-09-21-psd2022-knn" rel="alternate" type="text/html" title="Secure and non-interactive k-NN classifier using symmetric fully homomorphic encryption" /><published>2022-09-21T00:00:00+02:00</published><updated>2022-09-21T00:00:00+02:00</updated><id>https://yulliwasameur.github.io/publication/psd2022-knn</id><content type="html" xml:base="https://yulliwasameur.github.io/publication/2022-09-21-psd2022-knn"><![CDATA[]]></content><author><name>Yulliwas Ameur</name></author><summary type="html"><![CDATA[A non-interactive privacy-preserving k-NN classifier built on symmetric fully homomorphic encryption.]]></summary></entry></feed>