arXiv ScienceSearch

arXiv subjects

Chadi Assi

Publications and source records attributed to Chadi Assi.

At least 19 recordsLinked to original sources

Evidence-Grounded Retrieval for Investigation Hunt Lead Generation from CTI Reports

Threat hunting increasingly depends on converting unstructured knowledge (e.g., Cyber Threat Intelligence reports) into actionable hunt leads: concise, investigable hypotheses grounded in observable artifacts and adversary techniques. Producing such leads manually is a tedious and hard-to-scale task. Existing automated approaches stop at the entity layer, ignore the defender's operational environment, and analyze each report in isolation. To address these gaps, we introduce AHLERT, a system that automatically extracts relevant, environment-aware, and hunt leads from threat reports through (i) a hybrid retriever that combines dense vector search with multi-hop traversal over a knowledge graph seeded with MITRE ATT&CK; (ii) an ontology-grounding retrieval-augmented generation method that constrains each lead to the defender's own assets and controls; and (iii) an LLM-agnostic framework that emits structured, directly actionable leads rather than loose indicators of compromise. We evaluate AHLERT on public CTI reports for well-known APTs across multiple proprietary and open-weight models. Hybrid evidence retrieval with ontology grounding raises mean F1 by ~2x (0.44 to 0.85) over a single-route flat-RAG baseline, and AHLERT attains the highest effectiveness score (~86.95%) compared with off-the-shelf LLM models.

cs.CR

From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

Mechanisms for dynamically converting cyber threat intelligence (CTI) into actionable detection capabilities are necessary due to the rapid evolution of Advanced Persistent Threats (APTs). Sigma rules are an essential part of contemporary threat detection workflows because they offer a platform-independent framework for expressing detection logic that can be converted into particular queries across SIEM systems. Conventional techniques for manually crafting Sigma rules are prone to mistakes, and necessitate extensive knowledge, which restricts their scalability. Although there are open-source and industry-maintained Sigma rule repositories, they often fail to keep pace with emerging threats and require frequent customization to fit diverse operational environments. This emphasizes the necessity of dynamic rule generation that is adapted to evolving attack techniques as well as particular use cases. In this work, we design AUTOSIGMA, an automated solution for transforming unstructured CTI reports into relevant Sigma rules. Rather than relying solely on language models, AUTOSIGMA leverages a structured knowledge base to enrich partial inputs, matches the enriched content against a repository of existing Sigma rules, and then employs an LLM-as-a-Judge mechanism to iteratively validate the rules. By combining knowledge-driven enrichment, template-based rule grounding, and a multi-stage solution, AUTOSIGMA enables accurate, context-aware, and relevant rule generation. Evaluations across multiple real-world APT reports and multiple security blogs demonstrate that AUTOSIGMA outperforms alternative solutions and LLM models in rule validity, rule relevancy, MITRE ATT&CK technique coverage, and robustness to input quality. AUTOSIGMA's Demo: https://youtu.be/iSr6IurQ6BM

cs.CR

Secure Energy-Efficient Uplink Transmission in Movable-Element RIS-aided Systems with Movable Antennas and Artificial Noise

Secure energy efficiency (SEE) has emerged as a key performance metric for next-generation wireless networks, where energy sustainability and information security must be jointly guaranteed. This paper investigates secure uplink transmission in a full-duplex (FD) base station (BS) system equipped with movable antennas (MAs) and assisted by a movable-element reconfigurable intelligent surface (ME-RIS) in the presence of multiple cooperative passive eavesdroppers. The objective is to maximize SEE by jointly optimizing the users' transmit powers, BS receive postcoders, artificial noise (AN) transmit power and beamforming, RIS phase shifts, and the two-dimensional positions of both the BS antennas and RIS elements. The resulting optimization problem is highly nonconvex due to the fractional SEE objective, coupled secrecy-rate expressions, residual self-interference (SI), unit-modulus RIS phase-shift constraints, movable-position constraints, inter-element spacing requirements, and the nonlinear dependence of the channels on the movable antenna and RIS-element positions. To address these challenges, we propose a hybrid gradient-based meta-learning (H-GML) framework. In the proposed method, the BS receive postcoders and AN direction are updated using closed-form solutions derived from generalized Rayleigh quotient formulations, while the remaining coupled variables are updated by neural meta-optimizers that learn gradient-based update directions directly from the SEE optimization objective without requiring offline labeled training data. Simulation results show that the proposed H-GML design achieves better performance than the AO benchmark and significantly outperforms fixed-geometry, random RIS, no-AN, and no-Eve-knowledge baselines.

eess.SP

Movable Antenna Enhanced Dual-Functional Radar-Communication: A Symbol-Level Precoding Approach

This letter investigates a symbol-level precoder design for movable antenna (MA)-enhanced dual-functional radar-communication (DFRC) systems. To enhance radar sensing capabilities, we formulate an optimization problem aimed at maximizing the minimum radar signal-to-interference-plus-noise ratio (SINR) across multiple targets in a cluttered environment. Our approach jointly designs the space-time transmitted waveforms, receiving filters, and antenna placement. However, the resulting problem is intractable to solve due to practical waveform constraints and the non-linear mapping from antenna positions to the corresponding channel coefficients. To address these challenges, we develop a bi-level optimization framework by leveraging deep reinforcement learning (DRL). Specifically, the twin delayed deep deterministic policy gradient (TD3) algorithm is employed in the outer layer to optimize antenna placement, while penalty convex-concave procedure (CCP) and majorization-minimization (MM) techniques are incorporated in the inner layer for regularizing waveform design. Simulation results demonstrate that the proposed method significantly improves radar SINR and achieves a superior sensing-communication trade-off compared to benchmark schemes.

eess.SP

Joint Beamforming and Antenna Placement Optimization in Pinching Antenna Systems with User Mobility: A Deep Reinforcement Learning Approach

Recently, the pinching antenna systems (PASS) have attracted significant attention due to their ability to exploit dynamically reconfigurable pinching points along waveguides for flexible signal transmission. However, existing work largely overlooks user mobility although the optimal pinching configuration is highly dependent on the user's location and must be continuously adjusted. In this work, we investigate a PASS-enabled system model in which a base station (BS) serves a mobile user. We formulate an optimization problem that aims to maximize the user's average sum rate over a predefined time horizon while satisfying quality-of-service (QoS) constraint. This objective is achieved by jointly optimizing the beamforming vector at the BS and the pinching locations along the waveguides. Nevertheless, the resulting problem is highly non-convex and challenging to solve using conventional optimization techniques due to the intricate coupling among variables. The difficulty is further exacerbated by environmental randomness arising from user mobility and a probabilistic blockage model. This reveals a key engineering challenge: the performance gains of PASS critically rely on the ability to track or predict user trajectories in real time. To address these challenges, we adopt a deep deterministic policy gradient (DDPG) approach within a reinforcement learning framework, which is well-suited for continuous state and action spaces. Finally, extensive simulations are conducted to validate the proposed approach and demonstrate the importance of real-time configurability.

eess.SP

Optimizing Tracking Accuracy in Energy-Constrained Multimodal ISAC via Lyapunov-Driven Heterogeneous Mixture-of-Experts

The integration of multimodal sensing and millimeter-wave (mmWave) communications is a key enabler for highly mobile vehicle-to-infrastructure (V2I) networks. However, continuous high-resolution visual sensing incurs prohibitive computational energy, while delayed sensing information causes severe beam misalignment. This paper establishes a physics-aware multimodal integrated sensing and communication (M-ISAC) framework that mathematically bridges network-layer queuing delays with physical-layer spatial uncertainty via the semantic age of information (AoI). Guided by this relationship, we aim to strike an optimal trade-off between the tracking posterior Cramer-Rao bound (PCRB) and system energy budgets, we formulate a stochastic mixed-integer non-linear programming (MINLP) problem. Addressing the coupled challenges of temporal computing congestion and non-convex constant modulus constraints, we propose a reinforcement learning (RL) framework empowered by a Lyapunov-driven heterogeneous mixture-of-experts (LD-H-MoE) architecture. By strictly decoupling temporal scheduling and spatial phase mapping into specialized subnetworks, the LD-H-MoE circumvents gradient conflicts prevalent in monolithic multi-task learning. Simulations demonstrate that the proposed LD-H-MoE achieves a highly-effective event-triggered sensing policy, yielding superior tracking accuracy and radio-frequency (RF) resilience while guaranteeing edge computing queue stability and long-term energy budgets.

eess.SP

Heterogeneous Mixture-of-Experts for Energy-Efficient Multimodal ISAC in Highly Mobile Networks

The integration of multimodal sensing and millimeter-wave (mmWave) communications is a key enabler for highly mobile vehicle-to-infrastructure (V2I) networks. However, continuous high-resolution visual sensing incurs prohibitive computational energy, while delayed sensing information worsens beam misalignment. In this paper, we establish a physics-aware multimodel integrated sensing and communication (M-ISAC) framework that quantifies the mathematical trade-off between sensing energy and communication reliability using the semantic age of information (AoI). To address the coupled challenges of temporal AoI evolution and instantaneous non-convex constant modulus constraints, we propose a novel reinforcement learning approach empowered by a heterogeneous mixture-of-experts (RL-H-MoE) architecture. By strictly decoupling the temporal scheduling and spatial phase mapping, the RL-H-MoE avoids prevalent gradient conflicts in multi-task learning. Extensive simulations demonstrate that the proposed architecture achieves an optimal event-triggered sensing policy, significantly minimizing the long-term system cost while guaranteeing ultra-low sensing errors and reliable physical-layer link connectivity.

eess.SP

Joint Energy Efficiency Optimization for Uplink Multiuser Movable Antenna-Based Wireless Systems Assisted by Movable-Element RIS

This paper investigates energy efficiency (EE) optimization for an uplink multiuser system assisted by a movable-element reconfigurable intelligent surface (ME-RIS) and a base station equipped with movable antennas (MA-BS). We jointly optimize the uplink postcoder vectors, user transmit powers, RIS phase shift, and the positions of both the BS antennas and RIS elements to maximize the system EE. The resulting non-convex fractional problem is solved using an alternating optimization (AO) framework, where subproblems are handled via Dinkelbach's method combined with successive convex approximation (SCA). Simulation results show that the proposed scheme achieves significant EE gains over fixed-antenna BS and fixed-element RIS benchmarks.

eess.SP

Movable Antenna Empowered Covert Dual-Functional Radar-Communication

Movable antenna (MA) has emerged as a promising technology to flexibly reconfigure wireless channels by adjusting antenna placement. In this paper, we study a secured dual-functional radar-communication (DFRC) system aided by movable antennas. To enhance the communication security, we aim to maximize the achievable sum rate by jointly optimizing the transmitter beamforming vectors, receiving filter, and antenna placement, subject to radar signal-to-noise ratio (SINR) and transmission covertness constraints. We consider multiple Willies operating in both non-colluding and colluding modes. For noncolluding Willies, we first employ a Lagrangian dual transformation procedure to reformulate the challenging optimization problem into a more tractable form. Subsequently, we develop an efficient block coordinate descent (BCD) algorithm that integrates semidefinite relaxation (SDR), projected gradient descent (PGD), Dinkelbach transformation, and successive convex approximation (SCA) techniques to tackle the resulting problem. For colluding Willies, we first derive the minimum detection error probability (DEP) by characterizing the optimal detection statistic, which is proven to follow the generalized Erlang distribution. Then, we develop a minimum mean square error (MMSE)-based algorithm to address the colluding detection problem. We further provide a comprehensive complexity analysis on the unified design framework. Simulation results demonstrate that the proposed method can significantly improve the covert sum rate, and achieve a superior balance between communication and radar performance compared with existing benchmark schemes.

eess.SP

Joint Beamforming and Position Optimization for Movable-Antenna and Movable-Element RIS-Aided Full-Duplex 6G MISO Systems

Full-duplex communication substantially enhances spectral efficiency by enabling simultaneous transmission and reception on the same time-frequency resources. However, its practical deployment remains hindered by strong residual self-interference and inter-user interference, which severely degrade system performance. This work investigates a full-duplex MISO network that leverages movable-antenna base stations (MA-BS) and movable-element reconfigurable intelligent surfaces (ME-RIS) to overcome these limitations in next-generation 6G systems. Unlike conventional fixed-geometry architectures, the proposed framework jointly optimizes antenna and RIS element positions, together with RIS phase shifts, to strengthen desired links while suppressing interference. Our design objective is to maximize the system sum rate through the joint optimization of transmit and receive beamforming vectors, uplink transmit powers, RIS phase shifts, and the spatial locations of both the BS antennas and RIS elements. To solve this challenging nonconvex problem, an alternating optimization algorithm is developed, employing semidefinite relaxation for beamforming design and successive convex approximation for position optimization. Simulation results demonstrate that the proposed ME-RIS-assisted architecture with movable BS antennas offers substantial gains over conventional fixed-position full-duplex networks. These findings highlight the potential of integrating movable antennas with movable RIS elements as a key enabler for high-performance full-duplex operation in future 6G wireless systems.

eess.SP

Joint Power Control and Antenna Positioning for Uplink RSMA in Pinching Antenna Systems

This paper investigates a rate-splitting multiple access (RSMA) for uplink pinching antenna system (PASS). Our objective is to maximize the uplink sum rate by jointly optimizing a continuous antenna positioning and user's transmission power. The formulated problem is highly non-convex and difficult to solve directly; to address this challenge, we propose an alternating optimization (AO) framework which decomposes the original problem into two tractable sub-problems, namely (i) power allocation optimization sub-problem and (ii) antenna position optimization sub-problem. Both sub-problems are solved using successive convex approximation (SCA)-based algorithm and solved alternatively until convergence. The RSMA access for PASS is compared with conventional non-orthogonal multiple access (NOMA) and space-division multiple access (SDMA) techniques. The performance of discrete antenna activation with PASS strategy is also examined. Simulation results demonstrate that our proposed framework significantly enhances the achievable sum rate compared to other multiple access methods.

eess.SP

Joint Power Allocation and Radiation Optimization in NOMA-Assisted Pinching Antenna Systems

This paper explores a joint optimization of transmit power allocation and radiation coefficients in a downlink Pinching Antenna SyStem (PASS) employing Non-Orthogonal Multiple Access (NOMA). By leveraging the PASS-enabled flexible channel adjustment and NOMA's power allocation adaptability, a sum rate maximization problem is formulated with the objective of simultaneously optimizing base station (BS)'s transmit power coefficients and pinching antenna (PA)'s radiation powers. Due to its non-convexity and complexity, the formulated optimization problem is challenging to solve directly. Hence, we decompose the main problem into two sub-problems, namely transmit power allocation sub-problem and PA radiation power allocation sub-problem. In the first sub-problem, closed-form solutions are derived for the BS's power allocation among NOMA users. Meanwhile, in the second sub-problem, we optimize the PA's radiation power utilizing successive convex approximation (SCA). These two sub-problems are solved alternatively using Alternating Optimization (AO) until convergence. It should be noted that decoding order plays a significant role in NOMA-assisted PASS. Hence, two variations of decoding order are considered, namely: i) a high-complexity exhaustive search approach, and, ii) a low-complexity alternative that utilizes pre-determined channel information. Numerical results show that our proposed approach substantially improves the system's sum-rate compared to widely adopted equal power allocation PASS schemes.

eess.SP

Joint Uplink and Downlink Resource Allocation and Antenna Activation for Pinching Antenna Systems

In this paper, we explore a novel joint uplink and downlink framework utilizing a pinching antenna system (PASS). We consider two waveguides, one dedicated to transmission and one to reception, and both of them are connected to a base station (BS). Each type of waveguide consists of several pinching antennas (PAs) in some preconfigured positions. In this framework, we assume the BS can serve downlink and uplink user equipments (UEs) at the same time using the same spectrum resources through the presented PASS. In this aspect, we formulate a sum rate optimization problem that jointly optimizes the antenna activation factor, the BS transmit power, and the UE's transmit power, subject to power budget constraints for the BS and the UEs, as well as minimum rate requirements for the UEs. The formulated problem is highly non-convex and difficult to solve directly. Hence, we divide the main problem into two sub-problems: the antenna activation sub-problem and the power allocation sub-problem. Then, we solve the antenna activation problem utilizing a distance and spatial correlation-based algorithm. Meanwhile, the resource allocation problem is solved using a successive convex approximation (SCA)-based algorithm. Numerical results show that our proposed framework can achieve around 60-90\% performance gains over its time division duplex (TDD) where the uplink and downlink transmissions are served in different orthogonal time slots.

eess.SP

Coordinated Multipoint Transmission in Pinching Antenna Systems

We study a coordinated multi-point (CoMP) transmission where two base stations (BSs), each supported by a pinching antenna system (PASS), are deployed to jointly serve communication users under spatial division multiple access (SDMA) technology. Pinching Antenna technology was introduced as a promising solution to overcome the large-scale fading that has been shown to be an impediment in multiple-input multiple-output (MIMO) systems. To realize the advantages of this technology in CoMP systems, which suffer from an upperbound rate limitation when traditional uniform linear arrays (ULAs) are adopted, we formulate an optimization problem with the aim of maximizing the achievable sum rate by jointly determining the transmit beamforming vectors and pinching locations on the waveguides while respecting the quality of service (QoS) requirements of users. This problem is inherently non-convex due to the strong coupling among its decision parameters, making it challenging to solve using traditional optimization methods. Thus, we utilize a gradient-based meta-learning (GML) strategy specifically designed for large-scale optimization tasks. Finally, numerical analysis demonstrates the effectiveness of the proposed GML approach, achieving 92 percent of the optimal solution, and the superiority of the solution presented compared to other benchmarks. In addition, it achieves a higher upper bound on the achievable rate compared to conventional CoMP systems.

eess.SP

Movable Antenna Enhanced Covert Dual-Functional Radar-Communication: Joint Beamforming and Antenna Position Optimization

Movable antenna (MA) has emerged as a promising technology to flexibly reconfigure wireless channels by adjusting antenna placement. In this paper, we study a secured dual-functional radar-communication (DFRC) system enhanced by movable antennas. To ensure communication security, we aim to maximize the achievable sum rate by jointly optimizing the transmit beamforming vectors, receiving filter, and antenna placement, subject to radar signal-to-noise ratio (SNR) and transmission covertness constraints. To tackle this challenging optimization problem, we first employ a Lagrangian dual transformation process to reformulate it into a more tractable form. Subsequently, the problem is solved by employing a block coordinate descent (BCD) procedure, incorporating semidefinite relaxation (SDR), projected gradient descent (PGD), and successive convex approximation (SCA) techniques. Simulation results demonstrate that the proposed method can significantly improve the covert sum rate, and achieve a satisfactory balance between the communication and radar performance compared with existing benchmark schemes by leveraging the flexibility of movable antennas.

eess.SP

PUL-Inter-slice Defender: An Anomaly Detection Solution for Distributed Slice Mobility Attacks

Network Slices (NSs) are virtual networks operating over a shared physical infrastructure, each designed to meet specific application requirements while maintaining consistent Quality of Service (QoS). In Fifth Generation (5G) networks, User Equipment (UE) can connect to and seamlessly switch between multiple NSs to access diverse services. However, this flexibility, known as Inter-Slice Switching (ISS), introduces a potential vulnerability that can be exploited to launch Distributed Slice Mobility (DSM) attacks, a form of Distributed Denial of Service (DDoS) attack. To secure 5G networks and their NSs against DSM attacks, we present in this work, PUL-Inter-Slice Defender; an anomaly detection solution that leverages Positive Unlabeled Learning (PUL) and incorporates a combination of Long Short-Term Memory Autoencoders and K-Means clustering. PUL-Inter-Slice Defender leverages the Third Generation Partnership Project (3GPP) key performance indicators and performance measurement counters as features for its machine learning models to detect DSM attack variants while maintaining robustness in the presence of contaminated training data. When evaluated on data collected from our 5G testbed based on the open-source free5GC and UERANSIM, a UE/ Radio Access Network (RAN) simulator; PUL-Inter-Slice Defender achieved F1-scores exceeding 98.50% on training datasets with 10% to 40% attack contamination, consistently outperforming its counterpart Inter-Slice Defender and other PUL based solutions combining One-Class Support Vector Machine (OCSVM) with Random Forest and XGBoost.

cs.LG

Meta-Learning-Driven Resource Optimization in Full-Duplex ISAC with Movable Antennas

This paper investigates a full-duplex (FD) scenario where a base station (BS) equipped with movable antennas (MAs) simultaneously provides communication services to a set of downlink (DL) and uplink (UL) users while also enabling sensing functionalities for target detection, thereby supporting integrated sensing and communication (ISAC) technology. Additionally, a receiving BS, also equipped with MAs (denoted as BS R), is responsible for capturing the reflected echo. To optimize this setup, we formulate an optimization problem aimed at maximizing the signal-to-noise and interference ratio (SINR) of the captured echo. This is achieved by jointly optimizing the transmit beamforming vectors at the FD BS, the receiving beamforming vectors at both the FD BS and BS R, the UL users' transmit power, and the MAs' positions at both BSs, all while satisfying the quality-of-service (QoS) requirements for both sensing and communication. Given the non-convex nature of the problem and the high coupling between the variables, we employ a gradient-based meta-learning (GML) approach tailored for large-scale optimization. Numerical results demonstrate the effectiveness of the proposed meta-learning approach, achieving results within 99% of the optimal solution. Furthermore, the MA-based scheme outperforms several benchmark approaches, highlighting its advantages in practical ISAC applications.

eess.SP

Crosstalk-Resilient Beamforming for Movable Antenna Enabled Integrated Sensing and Communication

This paper investigates a movable antenna (MA) enabled integrated sensing and communication (ISAC) system under the influence of antenna crosstalk. First, it generalizes the antenna crosstalk model from the conventional fixed-position antenna (FPA) system to the MA scenario. Then, a Cramer-Rao bound (CRB) minimization problem driven by joint beamforming and antenna position design is presented. Specifically, to address this highly non-convex flexible beamforming problem, we deploy a deep reinforcement learning (DRL) approach to train a flexible beamforming agent. To ensure stability during training, a Twin Delayed Deep Deterministic Policy Gradient (TD3) algorithm is adopted to balance exploration with reward maximization for efficient and reliable learning. Numerical results demonstrate that the proposed crosstalk-resilient (CR) algorithm enhances the overall ISAC performance compared to other benchmark schemes.

eess.SP