Institution profile

University of La Rochelle

Academic institutioneurope · fr
Official website
Research library9linked papers
Opportunities0open roles
Selected work

Representative Papers

Advancing Autonomous Incident Response: Leveraging LLMs and Cyber Threat Intelligence

Aug 14, 2025

To address critical challenges in cybersecurity incident response—including alert fatigue, high false-positive rates, and inefficient utilization of unstructured cyber threat intelligence (CTI)—this paper proposes an intelligent analysis framework integrating large language models (LLMs) with retrieval-augmented generation (RAG). The method introduces a hybrid retrieval mechanism combining NLP-based semantic similarity search with standardized queries to external CTI platforms, enabling context-aware CTI enrichment. It further incorporates a two-tier expert cross-validation evaluation paradigm and integrates vector databases with multi-source CTI platforms to support semantic alert understanding and dynamic intelligence correlation. Experimental evaluation on both real-world and synthetic alert datasets demonstrates significant improvements: average response accuracy and contextual adaptability increase markedly, while mean response latency decreases by 37.2%. The framework delivers explainable, verifiable, and automated decision support for security operations centers.

0 citationsRead paper

Fuse and Federate: Enhancing EV Charging Station Security with Multimodal Fusion and Federated Learning

Jun 07, 2025

Electric vehicle supply equipment (EVSE) faces emerging multi-stage, cross-layer coordinated attacks—including network reconnaissance, backdoor implantation, and DDoS—rendering conventional intrusion detection systems (IDS) ineffective due to their inability to capture inter-layer exploit patterns. Method: We propose the first multimodal IDS framework integrating network traffic and kernel-level events. It tightly couples graph neural network (GNN)-based anomaly modeling with lightweight federated learning: multimodal feature alignment enables cross-layer behavioral representation; hierarchical federated aggregation and differential privacy–enhanced local updates ensure collaborative model evolution without data leaving premises. Contribution/Results: Evaluated on real-world EVSE deployments, our framework achieves 98.2% detection rate and 97.4% precision, reduces communication overhead by 37%, satisfies millisecond-scale response latency, and complies with GDPR requirements.

0 citationsRead paper
Recent publications

Latest Papers

Advancing Autonomous Incident Response: Leveraging LLMs and Cyber Threat Intelligence

Aug 14, 2025

To address critical challenges in cybersecurity incident response—including alert fatigue, high false-positive rates, and inefficient utilization of unstructured cyber threat intelligence (CTI)—this paper proposes an intelligent analysis framework integrating large language models (LLMs) with retrieval-augmented generation (RAG). The method introduces a hybrid retrieval mechanism combining NLP-based semantic similarity search with standardized queries to external CTI platforms, enabling context-aware CTI enrichment. It further incorporates a two-tier expert cross-validation evaluation paradigm and integrates vector databases with multi-source CTI platforms to support semantic alert understanding and dynamic intelligence correlation. Experimental evaluation on both real-world and synthetic alert datasets demonstrates significant improvements: average response accuracy and contextual adaptability increase markedly, while mean response latency decreases by 37.2%. The framework delivers explainable, verifiable, and automated decision support for security operations centers.

0 citationsRead paper

Fuse and Federate: Enhancing EV Charging Station Security with Multimodal Fusion and Federated Learning

Jun 07, 2025

Electric vehicle supply equipment (EVSE) faces emerging multi-stage, cross-layer coordinated attacks—including network reconnaissance, backdoor implantation, and DDoS—rendering conventional intrusion detection systems (IDS) ineffective due to their inability to capture inter-layer exploit patterns. Method: We propose the first multimodal IDS framework integrating network traffic and kernel-level events. It tightly couples graph neural network (GNN)-based anomaly modeling with lightweight federated learning: multimodal feature alignment enables cross-layer behavioral representation; hierarchical federated aggregation and differential privacy–enhanced local updates ensure collaborative model evolution without data leaving premises. Contribution/Results: Evaluated on real-world EVSE deployments, our framework achieves 98.2% detection rate and 97.4% precision, reduces communication overhead by 37%, satisfies millisecond-scale response latency, and complies with GDPR requirements.

0 citationsRead paper