The NOMS MCT — Management of Complex Threats workshop was held on 22 May 2026 in Rome, in conjunction with IEEE/IFIP NOMS 2026. The workshop looked at the next challenges in the coupling of cybersecurity and artificial intelligence, from zero-days and APTs to threats enabled by generative AI. Co-chairing it with Marc-Oliver Pahl (IMT Atlantique) was a great experience, and it’s time for a well-deserved thank-you to everyone who made it happen.
Thank you to the program committee
None of this runs without a program committee willing to review submissions on a tight schedule. Thank you to Amel Borgi, Ankush Meshram, Antonin Verdier, Christophe Biernacki, Conor Ryan, Ehsan Namjoo, Fatemeh Stodt, Francesco Mercaldo, Frédéric Le Mouël, Gilles Guette, Hamida Seba, Julien Michel, Layth Sliman, Léo Lavaur, Lisandro Zambenedetti Granville, Martin Husak, Mohamed-Lamine Messai, Mustafa Abdallah, Nidà Meddouri, Nour El Madhoun, Tristan Bilot, and Valeria Loscri.
Thank you to our keynote speaker
Fabio Brau (University of Cagliari) opened the workshop with a keynote on “Latent-Based Attacks Against Large Language Models” — a great framing for the discussions that followed throughout the day.
Thank you to the authors
Nine papers were presented, covering traffic classification, anomaly detection under concept drift, LLM-based honeypots, federated MCP gateways, autonomous IoT penetration testing, cyberattack detection in water distribution networks, multi-robot systems security, embedded anomaly detection, and SSH honeypot fingerprinting:
- Evidential k-NN: Interpretable Early Traffic Classification with Dempster-Shafer Theory — Andrea Gabriela Diaz Gardini, Alzbeta Pokorna, Jaroslav Pesek
- Multiclass Anomaly Detection in Streaming IoT Traffic under Concept Drift — Rodrigo Matos Carnier, Laura Lahesoo, Kensuke Fukuda
- CowLLMpot: Toward an LLM-Based Honeypot Fine-Tuned Using Cowrie Honeypot Data — Amal Rami, Adrien Fégar, Salam Doumiati Nasser, Ayman Alfalou
- A Federated MCP Gateway: Enforceable Isolation and Measuring Residual Semantic Attacks — Fatemeh Stodt, Christoph Reich, Jan Stodt
- ALIOTH: Orchestrating Multi-Agent LLMs for Autonomous IoT Penetration Testing — Francesco Aurelio Pironti, Luigi Arena, Francesco Blefari, Matteo Lupinacci, Francesco Romeo, Alessio Maresca, Angelo Furfaro
- Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks — Majed Jaber, Abdul Qadir Khan, Ankush Meshram, Julien Michel, Côme Frappé-Vialatoux, Pierre Parrend
- Modeling and Analysis of Bursty Delay Attacks in Cooperative Multi-Robot Systems — Rubal Sagwal, Vishal Gupta
- Real-time Instruction-Level Anomaly Detection for Embedded C-Functions using AI — Mohammed Mezaouli, Yehya Nasser, Samir Saoudi, Marc-Oliver Pahl
- Deception Detected: An Empirical Study of SSH Honeypot Detection and Fingerprinting in a Capture-the-Flag Competition — Mathis Durand, Yvon Kermarrec, Marc-Oliver Pahl
Thank you all for submitting, presenting, and discussing — see you at the next edition.
