Offre de stage : Explainable Anomaly Detection and Augmented Reality Visualization for Cybersecurity

Duration: 6 months
Supervision: Jean-Philippe Farrugia (LIRIS, Lyon 1), Mohamed-Lamine Messai (ERIC, Lyon 2) and Hamida Seba (LIRIS, Lyon 1)
Location: LIRIS, campus de la Doua Villeurbanne or IUT Lyon 1, campus de Bourg en Bresse
Application should be sent to: Hamida.seba@univ-lyon1.fr (CV+Transcripts)
Keywords: Cybersecurity, Computer Networks, Network Monitoring, Statistical
Anomaly Detection, Graph Analysis, Augmented Reality, WebXR, Immersive
Analytics.

Context and Summary

Modern computer networks generate continuous streams of heterogeneous data:
communications between hosts, user connections, service dependencies, authentication events, network flows, and security alerts.
Graphs provide a natural abstraction for representing such systems. Nodes
may represent hosts, users, services, processes, applications, or network devices,
while edges represent communications, accesses, dependencies, or information
flows.
Network activity can therefore be represented as a dynamic graph
Gt = (Vt,Et), whose structure evolves continuously over time.
A major challenge in cybersecurity monitoring is to identify abnormal behaviors
while preserving enough contextual information to understand why an
event is suspicious and how it relates to the surrounding network.
Many anomaly-detection approaches rely on complex machine-learning models.
Although powerful, their decisions can be difficult to interpret. In the
context of this internship, we deliberately focus on simple and explainable
statistical anomaly-detection methods.

The objective is to detect anomalies for which the reason for the detection
can be directly expressed through measurable network or graph properties, such
as:
• an unusually large number of communications;
• a sudden increase in traffic volume;
• communication with an unusually large number of destinations;
• abnormal values with respect to historical behavior;
• unusual local graph structure;
• abrupt changes in the neighborhood of a host;
• rare or unexpected communication patterns.
Such methods are particularly suitable for Augmented Reality (AR), since the statistical properties responsible for an anomaly can be directly translated into visual information presented to the analyst. The project already benefits from an existing WebXR prototype capable of visualizing streaming graphs in an immersive environment.
The objective of the internship is to transform this prototype into an experimental
platform for network monitoring and explainable anomaly investigation in Augmented Reality. The internship will investigate two complementary questions:
Which network-security monitoring and anomaly-investigation tasks
can benefit from an Augmented-Reality representation?
and
How can simple statistical anomaly-detection and graph-processing
methods be adapted so that detected anomalies and their causes are
directly visible and understandable in an immersive monitoring environment?

Candidate Profile

The internship is intended for a Master 2 student in Computer Science, Computer
Networks, Cybersecurity, or a related field.
The candidate should have:
• good programming skills;
• fundamental knowledge of computer networks: IP networking, TCP/UDP,
network flows, ports and common protocols;
• fundamental knowledge of cybersecurity: network attacks, intrusion detection,
security monitoring and logs;
• basic knowledge of statistics and data analysis;
• basic knowledge of algorithms and data structures.
Knowledge of graph algorithms, network monitoring tools, JavaScript/TypeScript,
Three.js, or WebXR would be appreciated [1], [2].

References

[1] Ricardo Cabello and Three.js Authors. Three.js: A javascript 3d library.
https://github.com, 2010. Accessed: 2026-09-14.
[2] W3C Immersive Web Working Group. Webxr device api. W3c working
draft, World Wide Web Consortium (W3C), 2026. Accessed: 2026-09-14.

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée. Les champs obligatoires sont indiqués avec *