<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pierre Parrend on Pierre Parrend — Cyber and AI</title><link>https://pparrend.github.io/</link><description>Recent content in Pierre Parrend on Pierre Parrend — Cyber and AI</description><generator>Hugo</generator><language>fr-fr</language><lastBuildDate>Fri, 14 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://pparrend.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>Contact</title><link>https://pparrend.github.io/contact/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/contact/</guid><description>&lt;ul>
&lt;li>&lt;strong>Email&lt;/strong>: pierre dot parrend &lt;em>at&lt;/em> epita dot fr&lt;/li>
&lt;li>&lt;strong>GitHub&lt;/strong>: &lt;a href="https://github.com/pierrep67">https://github.com/pierrep67&lt;/a>&lt;/li>
&lt;li>&lt;strong>LinkedIn&lt;/strong>: &lt;a href="https://fr.linkedin.com/in/pierreparrend">https://fr.linkedin.com/in/pierreparrend&lt;/a>&lt;/li>
&lt;li>&lt;strong>X&lt;/strong>: &lt;a href="https://x.com/pierrep67">https://x.com/pierrep67&lt;/a>&lt;/li>
&lt;/ul>
&lt;!--- **PGP Key**: [pgp-key.txt](/pgp-key.txt) — fingerprint: `XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX`--></description></item><item><title>CV / Skills</title><link>https://pparrend.github.io/cv/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/cv/</guid><description>&lt;img src="../images/illustrations/pierre.parrend.jpg" alt="Pierre Parrend" style="float: right; width: 250px; margin: 0 0 1rem 1rem;" />
&lt;h2 id="employment">Employment&lt;/h2>
&lt;h3 id="current-positions">Current positions&lt;/h3>
&lt;ul>
&lt;li>&lt;strong>Deputy Head of LRE - Laboratoire de Recherche de l&amp;rsquo;EPITA&lt;/strong> — since September 2022&lt;/li>
&lt;li>&lt;strong>Head of Security &amp;amp; Systems Teams @ LRE&lt;/strong> — since September 2022&lt;/li>
&lt;li>&lt;strong>Professor&lt;/strong> — EPITA, since May 2021&lt;/li>
&lt;li>&lt;strong>Researcher&lt;/strong> — Laboratoire ICube, since August 2012&lt;/li>
&lt;/ul>
&lt;h3 id="past-positions">Past positions&lt;/h3>
&lt;ul>
&lt;li>&lt;strong>Head of &amp;lsquo;Cybersecurity and Systems&amp;rsquo;&lt;/strong> major of the EPITA Engineer diploma (apprenticeship program), 2023-2026&lt;/li>
&lt;li>&lt;strong>Professor&lt;/strong> — ECAM Strabourg-Europe, 2018-2021&lt;/li>
&lt;li>&lt;strong>Department Head, Computer Science and Mathematics&lt;/strong> — ECAM Strasbourg-Europe, 2012–2021&lt;/li>
&lt;li>&lt;strong>Senior Researcher&lt;/strong> — Forschungszentrum Informatik (FZI), 2008–2012&lt;/li>
&lt;li>&lt;strong>PhD Student&lt;/strong> — INSA-Lyon, 2005–2008&lt;/li>
&lt;/ul>
&lt;h2 id="education">Education&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Habilitation à Diriger les Recherches&lt;/strong> — Université de Strasbourg, 2017&lt;/li>
&lt;li>&lt;strong>Doctorat en Informatique&lt;/strong> — INSA-Lyon, 2005–2008&lt;/li>
&lt;/ul>
&lt;h2 id="professional-activities">Professional Activities&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Member of the board&lt;/strong> — GDR Sécurité, GT SSLR, since September 2024&lt;/li>
&lt;/ul>
&lt;p>More on ORCID: &lt;a href="https://orcid.org/0000-0002-1680-1182">ORCID 0000-0002-1680-1182&lt;/a>&lt;/p></description></item><item><title>OTARQ: Adaptive and Automated Risk Quantification Method for OTA Updates in SDVs</title><link>https://pparrend.github.io/research/2026-otarq-risk-quantification-ota-sdv/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2026-otarq-risk-quantification-ota-sdv/</guid><description>&lt;p>The increasing frequency of Over-The-Air (OTA) updates on Software-Defined
Vehicles (SDVs), combined with heterogeneous OTA architectures, introduces
unpredictable attack entry points and vulnerabilities that may scale with
fleet size. These vulnerabilities can escalate from external infrastructure
components to in-vehicle systems, expanding the attack surface across the
update ecosystem. In SDV architectures, real-time vulnerability risk
management is challenging, as OTA updates may be deployed before
corresponding security patches are released and validated.&lt;/p></description></item><item><title>PTCC event — Cybersecurity of Critical Distribution Networks</title><link>https://pparrend.github.io/news/2026-08-14-cybersecurite-reseaux-distribution-critiques-ptcc/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/news/2026-08-14-cybersecurite-reseaux-distribution-critiques-ptcc/</guid><description>&lt;p>On 16 June 2026, &lt;a href="https://ptcc.fr/evenements/cybersecurite-des-reseaux-de-distribution-critiques/">PTCC&lt;/a>
(Programme de Transfert au Campus Cyber) hosted an afternoon at the
Auditorium Galaxy in Puteaux dedicated to the cybersecurity of critical
distribution networks — telecom, energy, drinking water — whose
architectures and operational constraints share common vulnerabilities.&lt;/p>
&lt;h2 id="program">Program&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Nicolas Prigent&lt;/strong> (PTCC/Inria) — introduction and a look back at
incidents analyzed by the Polish CERT&lt;/li>
&lt;li>&lt;strong>Stéphane Mocanu&lt;/strong> (Grenoble INP) — SCADA system vulnerabilities&lt;/li>
&lt;li>&lt;strong>Mathieu Galissot&lt;/strong> (CEA) — electric grid security and deception
techniques&lt;/li>
&lt;li>&lt;strong>Pérez Pelage&lt;/strong> (SecurZenn) — regulatory landscape (NIS2, Cyber
Resilience Act)&lt;/li>
&lt;li>&lt;strong>Nassim Bouiche&lt;/strong> (Sandfox) — critical infrastructure resilience&lt;/li>
&lt;li>&lt;strong>Léa Kenmogne&lt;/strong> (Grenoble INP) — AI-based attack detection&lt;/li>
&lt;li>&lt;strong>Lucas Georget&lt;/strong> (EDF R&amp;amp;D / LAAS-CNRS) — hardware-assisted malware
detection&lt;/li>
&lt;li>&lt;strong>Pierre Parrend&lt;/strong> (EPITA / ICube) — water distribution network
security, as part of the CoRREau project (ANR-22-CE39-0010)&lt;/li>
&lt;/ul>
&lt;h2 id="our-talk">Our talk&lt;/h2>
&lt;p>Our presentation covered cyberattack detection in water distribution
networks, building on work carried out within the ANR CoRREau project. It
extends the results published in
&lt;a href="https://pparrend.github.io/recherche/2024-combining-physical-network-data-wdn-attack-detection/">Combining Physical and Network Data for Attack Detection in Water Distribution Networks&lt;/a>
(WDSA/CCWI 2024) and in
&lt;a href="https://pparrend.github.io/recherche/2026-gpml-topology-attack-detection-water-networks/">Tool Demo: Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks&lt;/a>
(IEEE/IFIP NOMS 2026), which combine physical and network data to improve
attack detection on this type of infrastructure.&lt;/p></description></item><item><title>RedTeamLLM — Agentic AI framework for offensive security</title><link>https://pparrend.github.io/software/redteamllm/</link><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/software/redteamllm/</guid><description>&lt;p>From automated intrusion testing to discovery of zero-day attacks before
software launch, agentic AI calls for great promises in security
engineering. This strong capability is bound with a similar threat: the
security and research community must build up its models before the
approach is leveraged by malicious actors for cybercrime. This repository
implements &lt;strong>RedTeamLLM&lt;/strong>, an integrated architecture with a comprehensive
security model for automatization of pentest tasks. RedTeamLLM follows
three key steps — summarizing, reasoning, and act — which embed its
operational capacity, addressing plan correction, memory management,
context window constraints, and generality vs. specialization. Evaluation
is performed through the automated resolution of a range of entry-level,
but not trivial, CTF challenges.&lt;/p></description></item><item><title>NOMS MCT 2026 — Management of Complex Threats Workshop</title><link>https://pparrend.github.io/news/2026-08-14-noms-mct-2026-wrapup/</link><pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/news/2026-08-14-noms-mct-2026-wrapup/</guid><description>&lt;p>The &lt;a href="https://noms-mct.lre.epita.fr/">NOMS MCT — Management of Complex Threats&lt;/a>
workshop was held on 22 May 2026 in Rome, in conjunction with IEEE/IFIP
NOMS 2026. The workshop looked at the next challenges in the coupling of
cybersecurity and artificial intelligence, from zero-days and APTs to
threats enabled by generative AI. Co-chairing it with Marc-Oliver Pahl
(IMT Atlantique) was a great experience, and it&amp;rsquo;s time for a well-deserved
thank-you to everyone who made it happen.&lt;/p></description></item><item><title>SmartFlow — temporal data monitoring application</title><link>https://pparrend.github.io/software/smartflow/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/software/smartflow/</guid><description>&lt;p>SmartFlow (&amp;ldquo;Application de supervision de données temporelles&amp;rdquo; — temporal
data monitoring application) is a small Python stack for collecting and
visualizing sensor data over time. It is made of two parts: a harvester
(&lt;code>harvester.py&lt;/code>) that regularly retrieves sensor data from an origin server
and stores it as JSON, and a web application (&lt;code>app.py&lt;/code>) that serves the
collected data for analysis and monitoring. The deployment stack targets a
Linux server with gunicorn, Nginx, and supervisor.&lt;/p></description></item><item><title>Tool Demo: Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks</title><link>https://pparrend.github.io/research/2026-gpml-topology-attack-detection-water-networks/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2026-gpml-topology-attack-detection-water-networks/</guid><description>&lt;p>Water distribution networks depend on industrial control systems to
integrate the physical process with the communication network, making them
vulnerable to cyberattacks that alter traffic patterns and network behavior.
Traditional detection approaches that rely on raw traffic or protocol
information often overlook structural changes induced by such attacks.&lt;/p>
&lt;p>This work presents a topology-driven approach for detecting cyberattacks in
water distribution networks based on the Graph Processing for Machine
Learning (GPML) framework. Raw traffic is transformed into dynamic graphs,
from which community and spectral metrics are extracted and analyzed for
structural and communication modifications over time. The methodology is
evaluated on three industrial water distribution datasets — HITL, SWaT, and
CrossTest — and shows that spectral and community graph metrics improve
detection performance for both cyber and physical attacks across the three
datasets.&lt;/p></description></item><item><title>Congratulations Dr. Julien Michel</title><link>https://pparrend.github.io/news/2026-08-14-julien-michel-phd-defense/</link><pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/news/2026-08-14-julien-michel-phd-defense/</guid><description>&lt;p>Congratulations to &lt;strong>Julien Michel&lt;/strong>, who defended his PhD thesis,
&lt;em>&amp;ldquo;Détection d&amp;rsquo;attaques robuste en temps par métriques de communauté de
graphes&amp;rdquo;&lt;/em> (&amp;ldquo;Real-time robust attack detection using graph community
metrics&amp;rdquo;), on 8 April 2026 at the University of Strasbourg (ED 269,
ICube laboratory), under the supervision of Pierre Parrend.&lt;/p>
&lt;p>The work builds on the dynamic graph community metrics approach also
presented in
&lt;a href="https://pparrend.github.io/recherche/2025-t-robust-spaces-concept-drift-attack-detection/">t-robust spaces with dynamic graphs metrics for mitigating concept drift in attack detection&lt;/a>
(KES 2025).&lt;/p></description></item><item><title>Hybrid Evolutionary-ML Surrogate Models for Cyber-Attack Detection in Water Distribution Networks</title><link>https://pparrend.github.io/research/2026-hybrid-evolutionary-ml-surrogate-wdn-detection/</link><pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2026-hybrid-evolutionary-ml-surrogate-wdn-detection/</guid><description>&lt;p>Water distribution networks (WDNs), as critical infrastructure, face growing
cyber-attack risks. While Industry 4.0 initiatives motivate the deployment of
edge technologies for monitoring, efficient detection on distributed edge
devices requires methods that reduce computational overhead without
sacrificing classifier performance.&lt;/p>
&lt;p>We propose a hybrid evolutionary-machine learning (ML) approach that
constructs probabilistic surrogate models of trained ML classifiers using an
Estimation-of-Distribution Algorithm (EDA). Our het-EDA algorithm supports
the analysis of heterogeneous network communication features, extending
r-UMDA for categorical and PBIL-C for continuous data. It evolves class-wise
surrogates which optimize the original classifier&amp;rsquo;s output scores. Inference
is performed via lightweight log-likelihood evaluation, making the method
suitable for resource-constrained edge devices.&lt;/p></description></item><item><title>Presenting the Cloud Risk Mapping report at Forum InCyber 2026 (Lille)</title><link>https://pparrend.github.io/news/2026-08-14-cartographie-risques-cloud-incyber-lille/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/news/2026-08-14-cartographie-risques-cloud-incyber-lille/</guid><description>&lt;p>The report &lt;a href="https://wiki.campuscyber.fr/Cartographie_des_risques_dans_le_cloud">Cartographie des risques dans le Cloud&lt;/a>
(&amp;ldquo;Cloud Risk Mapping&amp;rdquo;), produced by the Campus Cyber working group of the
same name (part of the &amp;ldquo;Détection dans le Cloud&amp;rdquo; Community of Interest),
was presented at Forum InCyber 2026 in Lille.&lt;/p>
&lt;p>The document addresses the detection of potential or confirmed attacks on
digital production environments hosted on public, private, or hybrid
Cloud platforms. It proposes a multi-step approach:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Risk identification&lt;/strong>, tied to Cloud-specific features: access from
the Internet, shared virtualized environments, outsourced
administration and hosting&lt;/li>
&lt;li>&lt;strong>From risks to detection rules&lt;/strong>, illustrated with examples of major
incidents and a summary of the risk analysis&lt;/li>
&lt;li>&lt;strong>Detection rule coverage&lt;/strong>, with a deployment prioritization strategy
for monitoring tools and platforms&lt;/li>
&lt;/ul>
&lt;p>The Cloud risk list is organized by business value and by stakeholder —
whether the end user or the service provider — so that each party can
rethink its security event detection strategy according to its level of
Cloud usage.&lt;/p></description></item><item><title>GAML-MUDIT — Game Theory and Machine Learning for Multi-Domain Deception in Internet of Things</title><link>https://pparrend.github.io/projects/gaml-mudit/</link><pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/projects/gaml-mudit/</guid><description>&lt;p>&lt;em>Project period: 2025-2028&lt;/em>&lt;/p>
&lt;h2 id="presentation">Presentation&lt;/h2>
&lt;p>Cyber deception uses misleading information, decoys, and honeypots to shape an
attacker&amp;rsquo;s beliefs and actions. In a multi-domain cyber-physical system,
however, cyber and physical components are connected and a security decision in
one domain can affect the other. Designing deception strategies independently
can therefore leave inconsistencies that attackers may exploit.&lt;/p>
&lt;p>GAML-MUDIT studies a coordinated deception framework for Internet of Things
and cyber-physical environments, including critical infrastructures such as
water treatment systems. Game-theoretic models represent the interaction
between defenders and adversaries, while deep reinforcement learning supports
the prediction of attacker behavior and the adaptation of defensive actions.
Intent-based networking is also considered for orchestrating deception
automatically. The project aims to create believable, persistent cyber and
physical decoys that can adapt in real time without affecting genuine systems.&lt;/p></description></item><item><title>Software Defined Vehicle Security</title><link>https://pparrend.github.io/projects/sdv/</link><pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/projects/sdv/</guid><description>&lt;p>&lt;em>Project period: 2024-2027&lt;/em>&lt;/p>
&lt;h2 id="presentation">Presentation&lt;/h2>
&lt;p>Software-defined vehicles depend on frequent over-the-air updates and on a
distributed ecosystem of vehicle, network, and cloud components. This
architecture improves the ability to evolve vehicle software, but it also
creates new entry points for attacks and allows vulnerabilities to propagate
across entire fleets. Security decisions must therefore account for the
software update, the vehicle context, and the scale of deployment together.&lt;/p>
&lt;p>The project studies automated and adaptive methods for protecting this update
ecosystem. Its work combines cybersecurity, safety, and fleet-impact analysis
to quantify risks from natural-language vulnerability descriptions. It also
explores distributed update delivery using differential updates, peer-to-peer
content distribution, and coordinated vehicle-to-network and
vehicle-to-vehicle communication, including resilience under intermittent
connectivity.&lt;/p></description></item><item><title>Congratulations Dr. Majed Jaber</title><link>https://pparrend.github.io/news/2026-08-14-majed-jaber-phd-defense/</link><pubDate>Fri, 19 Dec 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/news/2026-08-14-majed-jaber-phd-defense/</guid><description>&lt;p>Congratulations to &lt;strong>Majed Jaber&lt;/strong>, who defended his PhD thesis,
&lt;em>&amp;ldquo;Structural and spectral analysis of dynamic graphs for attack
detection&amp;rdquo;&lt;/em>, on 19 December 2025 at the University of Strasbourg (ICube
laboratory), under the supervision of Pierre Parrend and Aline Deruyver.
The jury included Marc-Oliver Pahl, Véronique Legrand, Mohamed-Lamine
Messai, and Rushed Kanawati.&lt;/p>
&lt;p>The thesis introduces a spectral and structural graph-based framework for
detecting cyberattacks in dynamic, heterogeneous networks — including the
Spectral Time-Windowing method, the BiFlowness metric, and the open-source
&lt;a href="https://pparrend.github.io/projets/gpml/">GPML&lt;/a> library — building on work also presented in
&lt;a href="https://pparrend.github.io/recherche/2024-graph-based-spectral-analysis-cyber-attacks/">Graph-Based Spectral Analysis for Detecting Cyber Attacks&lt;/a>
(ARES &amp;lsquo;24) and
&lt;a href="https://pparrend.github.io/recherche/2025-cyberattack-detection-gpml-library/">Cyberattack detection through GPML: Graph Processing for Machine Learning&lt;/a>
(SoftwareX).&lt;/p></description></item><item><title>t-robust spaces with dynamic graphs metrics for mitigating concept drift in attack detection</title><link>https://pparrend.github.io/research/2025-t-robust-spaces-concept-drift-attack-detection/</link><pubDate>Wed, 10 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2025-t-robust-spaces-concept-drift-attack-detection/</guid><description>&lt;p>Concept drift is of primary concern for the detection of attacks in
Internet traffic networks. Those networks register a high diversity of
heterogeneous activity which change with usage, thus nurturing an evolutive
environment. Detecting attacks is the action of dissociating attacks from
the other data in the environment in a discriminating classification.
However, both the modification of attack behaviors through time and the
evolution of the environment are disruptive of the thin boundaries drawn by
learning models. For the evaluation of sustainability and trustworthiness
of the detection system, concept drift detection approaches have emerged.
Those approaches can necessitate a significant amount of time and resources
to mitigate the effect of concept drift thus detected.&lt;/p></description></item><item><title>AI4Sec — Artificial Intelligence for Cybersecurity</title><link>https://pparrend.github.io/teaching/ai4sec-artificial-intelligence-cybersecurity/</link><pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/ai4sec-artificial-intelligence-cybersecurity/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: APPING-2&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: S7&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 23h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: French&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary&lt;/h2>
&lt;p>The development of artificial intelligence tools is profoundly transforming cybersecurity professions in every domain: monitoring, penetration testing, vulnerability and threat research, code and script generation, summarizing complex cases, and security response preparation.&lt;/p>
&lt;p>This course first aims to define the main AI approaches — machine learning, language models — their use cases, and implementation best practices. It then provides useful tools for security operations, monitoring, and code and script generation.&lt;/p></description></item><item><title>Cyberattack detection through GPML: Graph Processing for Machine Learning</title><link>https://pparrend.github.io/research/2025-cyberattack-detection-gpml-library/</link><pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2025-cyberattack-detection-gpml-library/</guid><description>&lt;p>The dramatic increase of complex, multi-step, and rapidly evolving attacks
in dynamic networks involves advanced cyber-threat detectors. The GPML
(Graph Processing for Machine Learning) library addresses this need by
transforming raw network traffic traces into graph representations,
enabling advanced insights into network behaviors. The library provides
tools to detect anomalies in interaction and community shifts in dynamic
networks. GPML supports community and spectral metrics extraction,
enhancing both real-time detection and historical forensics analysis. This
library supports modern cybersecurity challenges with a robust, graph-based
approach.&lt;/p></description></item><item><title>DevSec — Secure Software Development</title><link>https://pparrend.github.io/teaching/devsec-secure-software-development/</link><pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/devsec-secure-software-development/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: ING3&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: Autumn&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 15h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: French (English possible)&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary&lt;/h2>
&lt;p>This course aims to teach the software development and deployment lifecycle, the categories of code vulnerabilities, and their instantiation in the C language. Design methodologies and development best practices are key tools for implementing these concepts in the software developed.&lt;/p>
&lt;p>Application is achieved through hands-on practice of the concepts studied, and through the development of a library or user software that applies these concepts.&lt;/p></description></item><item><title>Machine Learning for Cybersecurity</title><link>https://pparrend.github.io/teaching/machine-learning-for-cybersecurity/</link><pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/machine-learning-for-cybersecurity/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: ING3&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: Autumn&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 15h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: French (English possible)&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary&lt;/h2>
&lt;p>The growth of massive data flows within systems and networks, on one hand, and the increasing number and complexity of cyberattacks, on the other, make the automation of cybersecurity tools necessary in companies and organizations. Machine learning is a key technology for this automation: it enables the classification of traffic into known attack categories (supervised approach), and the identification of abnormal behavior (unsupervised approach).&lt;/p></description></item><item><title>SOC — Security Operating Centers</title><link>https://pparrend.github.io/teaching/soc-security-operating-centers/</link><pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/soc-security-operating-centers/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: APP-ING3&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: S10&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 15h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: Fr&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary&lt;/h2>
&lt;p>Security alert handling is performed by Security Operating Centers, or SOCs. A SOC operates technical alert-raising systems (IDS, SIEM) to analyze alerts, react to attacks, and prevent their recurrence. SOCs are associated with 3 levels of intervention: 1) handling of routine alerts; 2) alert analysis; 3) in-depth analysis and risk and threat management.&lt;/p>
&lt;h2 id="objectives">Objectives&lt;/h2>
&lt;p>After completing this module, students will be able to:&lt;/p></description></item><item><title>GPML — Graph Processing for Machine Learning</title><link>https://pparrend.github.io/software/gpml/</link><pubDate>Fri, 01 Aug 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/software/gpml/</guid><description>&lt;p>GPML has for purpose to give an easy to use tool to ready data for use to
machine learning algorithm using graph modelisation to compute new features
and insert them to pandas dataframe. It also comes with a module with one
ready function to use to convert dataset to html graph representation, some
examples are available in the &amp;ldquo;graph_representation&amp;rdquo; folder.&lt;/p>
&lt;p>See the &lt;a href="https://pparrend.github.io/recherche/2025-cyberattack-detection-gpml-library/">research paper&lt;/a>
presenting GPML for more background on the approach.&lt;/p></description></item><item><title>RedTeamLLM: an Agentic AI framework for offensive security</title><link>https://pparrend.github.io/research/2025-redteamllm-agentic-ai-offensive-security/</link><pubDate>Fri, 01 Aug 2025 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2025-redteamllm-agentic-ai-offensive-security/</guid><description>&lt;p>From automated intrusion testing to discovery of zero-day attacks before
software launch, agentic AI calls for great promises in security
engineering. This strong capability is bound with a similar threat: the
security and research community must build up its models before the
approach is leveraged by malicious actors for cybercrime. We therefore
propose and evaluate &lt;strong>RedTeamLLM&lt;/strong>, an integrated architecture with a
comprehensive security model for automatization of pentest tasks.
RedTeamLLM follows three key steps: summarizing, reasoning and act, which
embed its operational capacity. This novel framework addresses four open
challenges: plan correction, memory management, context window constraint,
and generality vs. specialization. Evaluation is performed through the
automated resolution of a range of entry-level, but not trivial, CTF
challenges. The contribution of the reasoning capability of our agentic AI
framework is specifically evaluated.&lt;/p></description></item><item><title>Graph-Based Spectral Analysis for Detecting Cyber Attacks</title><link>https://pparrend.github.io/research/2024-graph-based-spectral-analysis-cyber-attacks/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2024-graph-based-spectral-analysis-cyber-attacks/</guid><description>&lt;p>Spectral graph theory delves into graph properties through their spectral
signatures. The eigenvalues of a graph&amp;rsquo;s Laplacian matrix are crucial for
grasping its connectivity and overall structural topology. This research
capitalizes on the inherent link between graph topology and spectral
characteristics to enhance spectral graph analysis applications. In
particular, such connectivity information is key to detect low signals that
betray the occurrence of cyberattacks.&lt;/p>
&lt;p>This paper introduces &lt;strong>SpectraTW&lt;/strong>, a novel spectral graph analysis
methodology tailored for monitoring anomalies in network traffic. SpectraTW
relies on four spectral indicators — Connectedness, Flooding, Wiriness, and
Asymmetry — derived from network attributes and topological variations, that
are defined and evaluated. This method interprets networks as evolving
graphs, leveraging the Laplacian matrix&amp;rsquo;s spectral insights to detect shifts
in network structure over time. The significance of spectral analysis
becomes especially pronounced in the medical IoT domain, where the complex
web of devices and the critical nature of healthcare data amplify the need
for advanced security measures. Spectral analysis&amp;rsquo;s ability to swiftly
pinpoint irregularities and shifts in network traffic aligns well with the
medical IoT&amp;rsquo;s requirements for prompt attack detection.&lt;/p></description></item><item><title>Combining Physical and Network Data for Attack Detection in Water Distribution Networks</title><link>https://pparrend.github.io/research/2024-combining-physical-network-data-wdn-attack-detection/</link><pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/research/2024-combining-physical-network-data-wdn-attack-detection/</guid><description>&lt;p>Water distribution infrastructures are increasingly incorporating IoT in
the form of sensing and computing power to improve control over the system
and achieve greater adaptability to the water demand. This evolution, from
physical towards cyber-physical systems, comes with an attack perimeter
extended from physical infrastructure to the cyberspace. Being able to
detect this novel kind of attacks is gaining traction in the scientific
community. Machine learning detection algorithms, which are showing
encouraging results in cybersecurity applications, are leveraging the
increasing amount of datasets published in the water distribution community
for better attack detection. These datasets also begin to reflect this
novel cyber-physical aspect in two ways: first by conducting cyberattacks
against the testbed infrastructures during the data acquisition, and
second, by including network traffic data along with the physical data
captured during the experimentations.&lt;/p></description></item><item><title>IoT Security</title><link>https://pparrend.github.io/teaching/iot-security-summer-school/</link><pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/iot-security-summer-school/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: L1-L3&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: Summer School&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 18h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: En&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="objectives">Objectives&lt;/h2>
&lt;p>After completing this module, students will be able to:&lt;/p>
&lt;ul>
&lt;li>Explain and apply the principles of ethical hacking&lt;/li>
&lt;li>Explicit and apply responsible disclosure of vulnerabilities&lt;/li>
&lt;li>Characterise threats and actual attacks on IoT networks&lt;/li>
&lt;li>Analyse cyber attacks on IoT networks within the MITRE ATT&amp;amp;CK framework&lt;/li>
&lt;li>Detect vulnerabilities through scanning tools and methods&lt;/li>
&lt;li>Perform basic malware analysis through simple reverse engineering techniques&lt;/li>
&lt;/ul>
&lt;h2 id="lecture-outline">Lecture outline&lt;/h2>
&lt;ul>
&lt;li>Lectures
&lt;ul>
&lt;li>Ethical Hacking&lt;/li>
&lt;li>Network architectures and key features: IT, IoT&lt;/li>
&lt;li>The process of security audit: legal framework, reconnaissance, scan, exploitation, maintaining access&lt;/li>
&lt;li>IoT Malware&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>Exercices
&lt;ul>
&lt;li>IoT Malware: techniques and impacts&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>Lab Sessions
&lt;ul>
&lt;li>Building your own IoT network simulation&lt;/li>
&lt;li>Reconnaissance for IoT with Shodan search engine&lt;/li>
&lt;li>Scan for IT and IoT Networks&lt;/li>
&lt;li>Exploitation: Malware analysis&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul></description></item><item><title>TrustedIA — Intelligence Artificielle de Confiance</title><link>https://pparrend.github.io/teaching/trustedia-intelligence-artificielle-confiance/</link><pubDate>Mon, 01 Apr 2024 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/teaching/trustedia-intelligence-artificielle-confiance/</guid><description>&lt;ul>
&lt;li>&lt;strong>Level&lt;/strong>: L3&lt;/li>
&lt;li>&lt;strong>Semester&lt;/strong>: SI6&lt;/li>
&lt;li>&lt;strong>Duration&lt;/strong>: 12h&lt;/li>
&lt;li>&lt;strong>Language&lt;/strong>: Fr&lt;/li>
&lt;li>&lt;strong>Teacher&lt;/strong>: Pierre Parrend&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary&lt;/h2>
&lt;p>The use of so-called &amp;ldquo;artificial intelligence&amp;rdquo; algorithms in sensitive environments requires &amp;ldquo;trusted AI&amp;rdquo;. Trusted AI involves two elements: the ethical use of algorithms, and control over their results, in particular through explainability. The goal of this course is to provide methodological tools and case studies to learn how to develop trusted AI and control its properties.&lt;/p>
&lt;h2 id="objectives">Objectives&lt;/h2>
&lt;p>After completing this module, students will be able to:&lt;/p></description></item><item><title>XDGMed — Explainable Attack Detection Using Graphs for Medical Devices</title><link>https://pparrend.github.io/projects/xdgmed/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/projects/xdgmed/</guid><description>&lt;p>&lt;em>Project period: 2022-2025&lt;/em>&lt;/p>
&lt;h2 id="presentation">Presentation&lt;/h2>
&lt;p>Artificial intelligence is increasingly used to protect medical systems and
other high-risk environments, but security solutions must remain transparent,
traceable, and reviewable. XDGMed explores explainable attack detection by
representing complex analyses as meaningful graphs rather than relying only on
the opaque outputs of black-box models.&lt;/p>
&lt;p>The project develops spectral graph algorithms for explainable security analyses. Its
research focuses on dynamic graphs that model evolving environments, with
Laplacian analysis as the
main approaches. The work targets trustworthy cybersecurity for eHealth and
other sensitive systems, while following reproducible-research practices and
promoting open data and open-source software.&lt;/p></description></item><item><title>DAMIAGE — Detection of Attacks and Threats for Large-Scale Infrastructures</title><link>https://pparrend.github.io/projects/damiage/</link><pubDate>Sat, 01 Jan 2022 00:00:00 +0000</pubDate><guid>https://pparrend.github.io/projects/damiage/</guid><description>&lt;p>&lt;em>Project Phase 2: 01/2022-08/2024&lt;/em>&lt;/p>
&lt;h2 id="presentation">Presentation&lt;/h2>
&lt;p>Telecom operators and operators of vital importance need detection systems
that can keep pace with large, heterogeneous, and constantly changing
infrastructures. Conventional security operations center workflows collect
large volumes of NetFlow or IPFIX data, search for suspicious sequences, and
then decide whether to trigger a countermeasure. This passive model becomes
less suitable as the scale and diversity of IoT and critical-infrastructure
networks increase.&lt;/p>
&lt;p>DAMIAGE investigates a more active approach to attack detection. It leverages
network observations and uses graph-based analysis to
identify abnormal changes. The objective is to support detection in real time
or close to real time while developing security capabilities for critical
infrastructures in France.&lt;/p></description></item></channel></rss>