What are these working groups for?
Creach Labs is opening thirteen thematic working groups covering the whole cyber field. Each brings together researchers from the partner laboratories and experts from the DGA around a shared scientific and operational scope.
Each group relies on a mailing list intended to smooth exchanges between academic institutions and government bodies, within the scope of its own area.
The highlight: the annual dialogue meeting
It brings together all members of the group and serves to:
- review progress on ongoing projects;
- discuss each party's strategic vision for research and development;
- assess the potential for collaboration;
- set priorities for research to be pursued jointly;
- identify projects to be built together, with a view to the Creach Labs calls.
The rest of the year
The list keeps members in touch and carries the information the group needs:
- significant developments in the state of the art;
- steering of shared instruments (seminars, training);
- structural developments in academic and government institutions: recruitment, PhD and HDR defences, creation or reorganisation of teams, opening of platforms.
Leadership
Each group is led by a DGA lead, who runs the exchanges, sets the agenda of meetings and guides the discussions. The group is a tool for easing dialogue: it creates no obligation for its members.
Expand a topic below to see its scope, its lead and its contact address.
The thirteen working groups
-
This area covers the cryptographic primitives, protocols and mechanisms used to ensure the confidentiality, integrity, authenticity and non-repudiation of data and communications. It spans algorithm design, formal verification of their security and of their implementations, and the management of the cryptographic key and parameter life cycle. It underpins every other area, as the foundation of trust on which system protection mechanisms rest.
DGA lead: Laurent Boher
Contact: gt-crypto@listes.creachlabs.fr -
This area addresses the security of hardware and low-level software components — microprocessors, integrated circuits, firmware, embedded systems — considered as elements of trust within a security chain. It covers hardening these components against physical and logical attacks, assessing their robustness through hardware evaluation techniques (side channels, fault injection), and formally verifying the soundness of their design.
DGA lead: Rachid Dafali
Contact: gt-composants@listes.creachlabs.fr -
This area covers the threats and protection mechanisms specific to wireless transmission: unintentional electromagnetic emanations (TEMPEST), vulnerabilities in radio protocols and RF chains (Wi-Fi, Li-Fi, LoRa, 5G/6G), and the convergence of cybersecurity and electronic warfare. It addresses both passive attacks (interception, observation) and active ones (jamming, spoofing, injection) against wireless communication equipment.
DGA lead: Erwan Nogues
Contact: gt-sans-fil@listes.creachlabs.fr -
This area deals with the security of network infrastructure and communication protocols: hardening of existing protocols, network intrusion detection, adaptive monitoring, and secure architectures for enterprise networks and industrial systems. It also includes network stealth techniques and the detection of malicious flows, in particular in the presence of encryption.
DGA lead: Alain Seite
Contact: gt-reseaux@listes.creachlabs.fr -
This area covers the security of software layers close to the hardware: operating systems, hypervisors, virtualisation mechanisms, firmware and trusted execution environments. It spans both the secure design of these layers and their hardening against attack, and covers the formal specification of sound software architectures at this level of abstraction.
DGA lead: Louis Rilling
Contact: gt-couches-basses@listes.creachlabs.fr -
This area covers the security of applications and application-level software systems: web applications, APIs, databases, middleware and cloud services. It includes secure development techniques, vulnerability research in source code or binaries, and application penetration testing. It is closely tied to the “Languages and software engineering” area, of which it is the applied field oriented towards flaw detection.
DGA lead: Mickael Delahaye
Contact: gt-applicatif@listes.creachlabs.fr -
This area covers security-oriented software engineering methods and tools: formal languages, verification methods, program analysis (static, dynamic, symbolic), automatic code generation and assessment, fuzzing, software dependency management, obfuscation and diversification techniques, and the automatic construction of knowledge graphs from code. It provides the technical foundation shared by application security, malware analysis and vulnerability research.
DGA lead: Gurvan Le Guernic
Contact: gt-langages@listes.creachlabs.fr -
This area covers the design and assessment of hardware architectures from a security standpoint: processors (ARM, RISC-V, x86), memory, heterogeneity and CPU/GPU and RAM/VRAM hybridisation, and their specific attack surfaces. It includes formalising the security properties expected of an architecture and verifying them, as well as the threats specific to new platforms (micro-architectural side channels, hardware supply chain attacks). It also covers the security of hardware infrastructure for large-scale hosting.
DGA lead: Wilfried Gouret
Contact: gt-archi-materielle@listes.creachlabs.fr--- Panel 9 --- Title: 9. Software architecture Content (source mode):
This area covers the sound design of complex software systems: definition of security architectures, privilege separation, access control models, and formal verification of the security properties of software architectures. It complements the “Languages and software engineering” area by focusing on the architectural level rather than on code.
DGA lead: Norbert Douchin
Contact: gt-archi-logicielle@listes.creachlabs.fr -
This area covers the sound design of complex software systems: definition of security architectures, privilege separation, access control models, and formal verification of the security properties of software architectures. It complements the “Languages and software engineering” area by focusing on the architectural level rather than on code.
DGA lead: Norbert Douchin
Contact: gt-archi-logicielle@listes.creachlabs.fr -
This is the most cross-cutting area: it covers the security of information systems in their operational entirety, including industrial systems and the IoT. It brings together intrusion detection, security monitoring, decision support and human factors. It is the integration level above the technical layers, where incident response is handled and the defensive posture is built. Threat intelligence belongs to area 13.
DGA lead: Frédéric Majorczyk
Contact: gt-it-ot-iot@listes.creachlabs.fr -
This area covers the human and social dimensions of the cyber threat, in particular influence and manipulation operations exploiting social networks, digital media and human behaviour. It spans disinformation and deepfake detection, behavioural analysis of online communities, stylometry, attribution of influence operations and counter-narrative capabilities.
DGA lead: Colas Hummel
Contact: gt-ingenierie-sociale@listes.creachlabs.fr -
This area deals with the security of systems incorporating artificial intelligence, both as a target of attack (adversarial attacks, data poisoning, model theft, evasion) and as a vector or amplifier of attack. It also includes explainability as a prerequisite for trust in AI systems used defensively, the detection of unauthorised embedded AI models, and the measurement and monitoring of model training quality.
DGA lead: Igor Sguario
Contact: gt-cyber-ia@listes.creachlabs.fr -
This area brings together work on understanding and characterising attackers, their modes of operation and their technical capabilities. It covers cyber threat intelligence, the analysis of offensive techniques (vulnerability exploitation, defence evasion), attribution methods, and the formalisation of threat knowledge (ontologies, knowledge bases). It is essential to every field of cyber operations.
DGA lead: to be appointed
Contact: gt-menace@listes.creachlabs.fr
Sensitivity of exchanges
These mailing lists are not encrypted and their messages travel in clear text. They must never be used to exchange confidential, protected or classified information. Anything sensitive belongs on the channels provided for that purpose.
Join a working group
To be added to one of these lists, or for any question about the initiative, write to the lead of the group concerned or to the Creach Labs contact address.