Professor of Cybersecurity
Trustworthy Autonomous Cybersecurity · Critical Infrastructures · Distributed Systems

I study how complex digital infrastructures can establish trustworthy security state, understand adversarial behaviour, and respond safely under increasing autonomy. My research connects distributed systems and network management with cyber-physical and embedded security, trustworthy AI, contextual reasoning, autonomous response, and human decision-making.
I am Professor of Cybersecurity at IMT Atlantique and Chairholder of the Cybersecurity for Critical National Infrastructures (Cyber CNI) Chair, a multi-institutional research ecosystem spanning IMT Atlantique, Télécom Paris, and Télécom SudParis.
Google Scholar · DBLP · ORCID · HAL · LinkedIn · Cyber CNI
Research
From observation to self-healing cybersecurity
observe → understand → decide → act → verify → learn
Digital infrastructures increasingly combine embedded devices, networks, cloud and edge services, cyber-physical processes, AI components, organizations, and human operators. Attacks do not respect the boundaries between these layers.
My overarching question: How can complex digital infrastructures remain trustworthy when the systems they protect, the evidence they expose, the AI they employ, and the adversaries they face are all changing simultaneously?
Trustworthy Observability — What evidence can a defender trust? I investigate security observability across network telemetry, cyber-physical processes, honeynets, embedded execution, and physical side channels—from distributed anomaly detection to power-assisted security analysis.
Contextual Security Reasoning — How can heterogeneous observations become security knowledge? Building on semantic integration and distributed systems, I investigate system models, provenance, uncertainty, digital twins, and hybrid AI for contextual security reasoning.
Autonomous Resilience — Under what conditions may cybersecurity act autonomously? My work connects distributed and federated intelligence, AIOps, digital twins, consequence assessment, and graduated autonomy toward increasingly self-healing infrastructures.
Meaningful Human Control — How should cognition and authority be divided between humans and machines? Building on computer graphics, virtual reality, and immersive cybersecurity analytics, I investigate decision support that reduces rather than adds complexity.
Emerging frontier — Information Resilience — My recent work extends these questions to AI-mediated information systems: controlled generation, disinformation, provenance, human response, and operation-level observability.
Selected Research
- The Evolution of Federated Learning-Based Intrusion Detection and Mitigation: A Survey
IEEE Transactions on Network and Service Management, 2022 — Distributed and collaborative cyber defence. - Multipath Neural Networks for Anomaly Detection in Cyber-Physical Systems
Annals of Telecommunications, 2023 — Multi-signal observability for cyber-physical security. - RADAR: Model Quality Assessment for Reputation-aware Collaborative Federated Learning
IEEE SRDS, 2024 — Trustworthy collaborative learning under unreliable contributions. - Shells Bells: Cyber-Physical Anomaly Detection in Data Centers
IEEE/IFIP NOMS, 2024 — Physical infrastructure as complementary security evidence. - Real-Time AI-Based Power-Assisted Vulnerability Detection
IEEE/IFIP NOMS, 2026 — Physical observability below potentially compromised software. - Experts Disagree on How to Fight AI Disinformation, but Agree that Health and Politics Need Different Solutions
Harvard Kennedy School Misinformation Review, 2026 — Emerging research on resilient AI-mediated information ecosystems.
Complete publication record (DBLP) · Google Scholar
Group & Experimental Research
I organize research around scientific questions rather than individual funding instruments. Projects provide the people, infrastructure, data, and experimental environments required to pursue these questions over time.
Current doctoral researchers — Christian Lübben · Erkin Kirdan · Alexander Loth · Mathis Durand · Mohammed Mezaouli · Hugo Bourreau · Luc Bournaud · Antonios Ntib
Research engineering — Axel Dupraz
The current team spans IMT Atlantique, TUM, Frankfurt University of Applied Sciences, and Western University, with work on distributed AI, industrial IoT, cyber deception, embedded physical observability, digital twins, decentralized incident response, and AI-enabled information resilience.
Industrial & OT Security — Miniaturized industrial factories with Siemens, Schneider, Industrial Shields, and Crouzet PLCs; PLC-controlled physical processes; smart-building IoT; and a virtualized environment reproducing major real-world OT attacks.
Embedded & Physical Security — Experimental environments for embedded execution analysis, power-assisted security observability, and side-channel research.
Digital-Twin Security — Experimental twins of water-treatment processes and IoT systems for state estimation, adversarial manipulation, attribution, and resilience.
Cyber Deception — Honeynet deployments and tooling for analysing realism, detectability, fingerprinting, and attacker interaction.
Immersive Cybersecurity Analytics — A multi-user VR environment for situational awareness, immersive analytics, risk analysis, and mitigation control.
Information Resilience — JudgeGPT/RogueGPT, CRED-1, and experimental infrastructure for controlled AI-generated information, provenance, and human-response studies.
Semantic Distributed Systems — A VSL-based testbed for semantic collaboration among distributed agents using a dynamically evolving knowledge model.
JudgeGPT experimental interface · labsystem / iLab infrastructure
Cybersecurity for Critical National Infrastructures
I lead the Cyber CNI Chair, connecting fundamental cybersecurity research with the constraints of real critical infrastructures. The programme has evolved from distributed and federated detection toward cyber-physical observability, deception, embedded and physical security evidence, digital twins, and autonomous response.
Current industrial partners — Airbus Programme Cyber · Airbus PROTECT · EDF · RTE · Astek
Public and institutional ecosystem — COMCYBER · Pôle d’Excellence Cyber · Campus Cyber · Région Bretagne · FEDER
Previous industrial partners include — SNCF · BNP Paribas · Nokia · Amossys · Orange · La Poste · Société Générale
Research at Scale
| 70+ | peer-reviewed publications | 1,590 | Google Scholar citations |
| ~€7M | research funding acquired as PI | 20 | H2020 / Horizon Europe proposals |
| 19 | doctoral researchers supervised/co-supervised | 150 | Bachelor’s and Master’s theses |
h-index 18 · i10-index 45 · 5 Horizon consortium coordinator roles · figures updated September/October 2026.
Selected programmes include Cyber CNI, Horizon Europe CyberSecDome, AI-based embedded-security projects, DTACK, Atos Life-Cycle Based IoT Service Management, DECENT, and Building as a Service.
Three Latest Publications
RogueGPT: A Controlled Stimulus Generation Framework for News Authenticity Research
RogueGPT is an open-source Python framework for the controlled, reproducible generation and curation of multilingual news fragments for AI authenticity research. It enables researchers to systematically produce synthetic news stimuli across a wide range of large language model (LLM) families, journalistic styles, languages, and content formats, while storing every fragment alongside complete generation provenance in…
AI-Enhanced Security Tools with Virtual Reality for Ensuring Digital Resilience
The cybersecurity challenges facing today’s digital infrastructure make it critical to improve the disruption preparedness and resilience of these systems. Resilience can only be achieved through (i) having a clear and comprehensive understanding of cyber incidents and their cascading effects, including potential disruptions, and (ii) providing a system with dynamic recovery and response capabilities. The…
Experts disagree on how to fight AI disinformation, but agree that health and politics need different solutions
When 54 international experts assessed AI-generated disinformation threats, they revealed a surprising pattern: while video deepfakes received the highest average threat ratings in the political domain (M = 6.31/7), the pattern differed in the health domain, where AI-generated text received the highest average rating (M = 5.80). Experts also diverge on what to do: government…
Teaching
I have taught continuously at universities for more than twenty years. I regard teaching as a design discipline: learning objectives, activities, assessment, feedback, technology, and the learning environment should form a coherent system.
My principal educational contribution is iLab / labsystem, developed over two decades into a methodology and open-source infrastructure for scalable hands-on computer science education. Its formats have reached thousands of learners across physical and virtual laboratories, MOOCs, hybrid teaching, and learning-by-teaching.
Representative formal evaluation — 1.4 overall · 1.2 practical relevance · 1.1 commitment to student success (1 = best).
Recognition includes the Ernst Otto Fischer Teaching Prize, three TUM Teaching Excellence Awards, and the TUM Supervisory Award. I hold TUM’s ProLehre Certificate for Professional University Teaching, Advanced Level.
I am currently extending this methodology toward hands-on OT cybersecurity education.
Education in the age of AI — when AI can generate convincing programs, explanations, and reports almost instantly, assessment must increasingly evaluate reasoning → experimentation → critique → evidence → reflection.
Academic Leadership
My academic career spans the German and French research systems. At TUM, I was the first scientific staff member of the newly established Chair of Network Architectures and Services. In Rennes, I built a research operation essentially from the ground up and subsequently revitalized and expanded Cyber CNI.
My leadership philosophy is based on progressive transfer of intellectual ownership: develop researchers who can define and lead their own science, build structures that outlast individual projects, and connect communities in ways that enable research none could achieve alone.
President · German Chapter of the ACM
Member of the Präsidium · Gesellschaft für Informatik
Technical Program Co-Chair · IEEE/IFIP NOMS 2026
Distinguished Expert Panel Co-Chair · CNSM 2026
Additional roles include leadership in the German-French Academy for the Industry of the Future, Lab-Cyber/Campus Cyber, journal editorial boards, and guest editorships on AI/MLOps, Industrial IoT, and trustworthy Agentic AI.
Academic Background
Habilitation in Computer Science — Technical University of Munich, 2025
Dr. rer. nat., summa cum laude — Technical University of Munich, 2014
Diplom in Computer Science, grade 1.0 — University of Tübingen, 2007
My scientific foundations lie in distributed systems, computer networks, semantic integration, and computer graphics, complemented by media science. This combination continues to shape my approach to cybersecurity across technical layers and human decision-making.
Knowledge Transfer & Society
I engage in knowledge transfer where it strengthens research, education, or societal understanding. My activities include long-term collaboration with critical-infrastructure operators and cybersecurity organizations, open-source research and teaching infrastructure, MOOCs, international doctoral schools, and public discussion formats.
TALK.CYBER · Future-IoT · German Chapter of the ACM
I regard transfer and entrepreneurship as consequences of excellent research, not substitutes for it.
Latest
Aufruf zu Nominierungen für den Albert-Endres-Award 2027 Posted in: ACM, announcements, CfP, Mitgliederinfo, Mitgliederversammlung- Wenn KI unsere Informationswelt verändert: German Chapter Workshop zu Desinformation beim INFORMATIK FESTIVAL 2026 Posted in: announcements, CfP, GI/GChACM Kollaboration, Mitgliederinfo, Veranstaltungen
Heidelberg Laureate Forum 2026: Informatikgeschichte erleben – und live dabei sein Posted in: announcements, Mitgliederinfo, Veranstaltungen
European Innovation Ecosystems: Lessons from Ten Years of the German-French Academy for the Industry of the Future Posted in: GFA, Press, Press Coverage Update, Press Release, Projets, Publications, Research, Strategy, SummerSchool, Teaching, Team
France’s Cybersecurity Chairs Unite at the École Militaire: Strengthening a National Ecosystem for Cybersecurity Research Posted in: Actualités, announcements, Cyber CNI, Évènement, Event, Press
Critical Infrastructure Cyber Resilience at Eurosatory 2026: Strengthening France’s and Europe’s Cyber Defence Ecosystem Posted in: airbus, announcements, Cyber CNI, Évènement, Event, Partenaires, Press, Research
CyberSecDome Final Plenary Meeting Brings Partners Together in Chania Posted in: Actualités, airbus, Cyber CNI, CyberSecDome, EU, Évènement, Event, Projects, Projets
Digitale Souveränität: Infrastruktur, Macht oder Gesellschaftsprojekt? Posted in: ACM, Jahresveranstaltung 2026, Mitgliederversammlung, Veranstaltungen
CyberSecDome XR Cybersecurity Demo at IRISA Posted in: Actualités, announcements, Évènement, Event, News
Wrapping Up an Inspiring Journey in the New Master Cybersecurity Program at IMT Atlantique Posted in: Actualités, Cyber CNI, News, Teaching