VLDB 2026 Research / reviewers in the wild / expert
Lorena González-Manzano
dblp:119/3531
· DBLP profile ↗
34ranked-venue papers
13as first author
16since 2021 · last 2026
0000-0002-3490-621XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 7 first-author · 9 since 2021Systems, architecture and hardware · 6 · 2 first-author · 2 since 2021Computer networks · 4 · 3 first-authorArtificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Assessing the Operational Impact of Poisoning Attacks over Augmented 3D Point Cloud Public Datasets for Connected and Autonomous VehiclesabstractInternational audience Marwan Lazrag, Badis Hammi, Lorena González-Manzano, Joaquín García 0001 |
SECRYPT (1) | 3 |
| 2025 | Service-Aware Password Risk Meter - Helping Users to Choose Suitable Passwords in Services
Roi S. Serna, Ana I. González-Tablas, Lorena González-Manzano, José María de Fuentes |
ARES (2) | 3 |
| 2025 | LUMIA: Linear Probing for Unimodal and MultiModal Membership Inference Attacks Leveraging Internal LLM States
Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Nicolas Anciaux, Joaquín García 0001 |
ESORICS (1) | 2 |
| 2025 | Large language models can learn and generalize steganographic chain-of-thought under process supervisionabstractChain-of-thought (CoT) reasoning not only enhances large language model performance but also provides critical insights into decision-making processes, marking it as a useful tool for monitoring model intent and planning. By proactively preventing models from acting on CoT indicating misaligned or harmful intent, CoT monitoring can be used to reduce risks associated with deploying models. However, developers may be incentivized to train away the appearance of harmful intent from CoT traces, by either customer preferences or regulatory requirements. However, recent works have shown that banning the mention of a specific example of reward hacking causes obfuscation of the undesired reasoning traces but the persistence of the undesired behavior, threatening the reliability of CoT monitoring. However, obfuscation of reasoning can be due to its internalization to latent space computation, or its encoding within the CoT. We provide an extension to these results with regard to the ability of models to learn a specific type of obfuscated reasoning: steganography. First, we show that penalizing the use of specific strings within load-bearing reasoning traces causes models to substitute alternative strings. Crucially, this does not alter the underlying method by which the model performs the task, demonstrating that the model can learn to steganographically encode its reasoning. This is an example of models learning to encode their reasoning. We further demonstrate that models can generalize an encoding scheme. When the penalized strings belong to an overarching class, the model learns not only to substitute strings seen in training, but also develops a general encoding scheme for all members of the class which it can apply to held-out testing strings. Robert MC Carthy, Joey Skaf, Luis Ibañez-Lissen, Vasil Georgiev, Connor Watts, Hannes Whittingham, Lorena González-Manzano, Cameron Tice, Edward James Young, Puria Radmard, David Lindner |
NeurIPS | 7 |
| 2025 | Detecting Multi-Turn Jailbreak Attacks in Large Language Models via Linear ProbesabstractMulti-turn jailbreak attacks are a prominent threat for Large Language Models (LLMs). While internal LLM data has been used for single-turn jailbreaks, its suitability for multi-turn ones remains unexplored. This paper proposes a mechanism leveraging linear probes on layer activations. Interestingly, it enables characterizing the anticipation (or Early Warning, EW) in the detection, which has never been measured. To support the assessment, a novel dataset with +10k harmful and harmless conversations is produced. Experiments on Llama, Qwen and Mistral models show that the approach is specially effective in Llama – for 5-turn attacks, max F1=0.7 and average EW =2.64). Moreover, our results suggest that the effectiveness decreases with bigger model sizes. Jorge Marina-Metola, José María de Fuentes, Lorena González-Manzano, Luis Ibañez-Lissen |
TrustCom | 3 |
| 2025 | On the Resilience of Traditional AI Algorithms Toward Poisoning Attacks for Vulnerability DetectionabstractThe complexity of implementations and the interconnection of assorted systems and devices facilitate the emergence of vulnerabilities. Detection systems are developed to fight against this security issue, being the use of artificial intelligence (AI) a common practice. However, the use of AI is not without its problems, especially those affecting the training phase. This article tackles this issue by characterizing the resilience against poisoning attacks using a benchmark for vulnerability detection, extracting simple code features while applying traditional AI algorithms. These choices are beneficial for the fast processing of vulnerabilities required in a triage process. The study is carried out in C#, C/C++, and PHP. Results show that the vulnerability detection process is specially affected beyond 20% of false data. Remarkably, detecting some of the most frequent common weakness enumeration (CWE) is altered even with lower poison rates. Overall, K ‐nearest‐neighbor (KNN) and support vector machine (SVM) are the most resilient in C# and C/C++, while multilayer perceptron (MLP) in PHP. Indeed, vulnerability detection in PHP is less affected by attacks, while C# and C/C++ present comparable results. Lorena González-Manzano, Joaquín García 0001 |
IET Inf. Secur. | 1 |
| 2025 | LPASS: Linear Probes as Stepping Stones for vulnerability detection using compressed LLMsabstractLarge Language Models (LLMs) are being extensively used for cybersecurity purposes. One of them is the detection of vulnerable codes. For the sake of efficiency and effectiveness, compression and fine-tuning techniques are being developed, respectively. However, they involve spending substantial computational efforts. In this vein, we analyze how Linear Probes (LPs) can be used to provide an estimation on the performance of a compressed LLM at an early phase — before fine-tuning. We also show their suitability to set the cut-off point when applying layer pruning compression. Our approach, dubbed L P A S S , is applied in BERT and Gemma for the detection of 12 of MITRE’s Top 25 most dangerous vulnerabilities on 480k C/C++ samples. LPs can be computed in 142.97 s. and provide key findings: (1) 33.3 % and 72.2% of layers can be removed, respectively, with no precision loss; (2) they provide an early estimate of the post-fine-tuning and post-compression model effectiveness, with 3% and 8.68% as the lowest and average precision errors, respectively. L P A S S -based LLMs outperform the state of the art, reaching 86.9% of accuracy in multi-class vulnerability detection. Interestingly, L P A S S -based compressed versions of Gemma outperform the original ones by 1.6% of F1-score at a maximum while saving 29.4 % and 23.8% of training and inference time and 42.98% of model size. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Nicolas Anciaux |
J. Inf. Secur. Appl. | 2 |
| 2025 | Use of Transfer Learning for Affordable In-Context Fake Review GenerationabstractFake content is a noteworthy threat which is managed by assorted means. This is a serious problem for online shopping platforms whose products can be affected by negative or positive reviews. Artificial intelligence is commonly applied for fake review generation, being transfer learning a promising approach to reduce training requirements. However, the feasibility of generating in-context fake reviews using transfer learning has not been explored yet. This paper analyses the suitability of a couple of transformers (T5 and BART) to generate realistic in-context fake reviews. Results show that 1) the diversity of generated reviews is comparable to existing works; 2) human-based detection is close to random; 3) just reviews generated with one of the used transformers can be detected with 38% precision; and 1 h of training and 8 k real reviews are needed to produce realistic fake reviews. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Manuel Goyanes |
IEEE Trans. Big Data | 2 |
| 2024 | Continuous Authentication Leveraging Matrix ProfileabstractContinuous Authentication (CA) mechanisms involve managing sensitive data from users which may change over time. Both requirements (privacy and adapting to new users) lead to a tension in the amount and granularity of the data at stake. However, no previous work has addressed them together. This paper proposes a CA approach that leverages incremental Matrix Profile (MP) and Deep Learning using accelerometer data. Results show that MP is effective for CA purposes, leading to 99% of accuracy when a single user is authorized. Besides, the model can on-the-fly increase the set of authorized users up to 10 while offering similar accuracy rates. The amount of input data is also characterized – the last 15 s. of data in the user device require 0.4 MB of storage and lead to a CA accuracy of 97% even with 10 authorized users. Luis Ibañez-Lissen, José María de Fuentes, Lorena González-Manzano, Nicolas Anciaux |
ARES | 3 |
| 2024 | On the Feasibility of Predicting Volumes of Fake News - The Spanish CaseabstractThe growing amount of news shared on the Internet makes it hard to verify them in real-time. Malicious actors take advantage of this situation by spreading fake news to impact society through misinformation. An estimation of future fake news would help to focus the detection and verification efforts. Unfortunately, no previous work has addressed this issue yet. Therefore, this work measures the feasibility of predicting the volume of future fake news in a particular context—Spanish contents related to Spain. The approach involves different artificial intelligence (AI) mechanisms on a dataset of 298k real news and 8.9k fake news in the period 2019–2022. Results show that very accurate predictions can be reached. In general words, the use of long short-term memory (LSTM) with attention mechanisms offers the best performance, being headlines useful when a small amount of days is taken as input. In the best cases, when predictions are made for periods, an error of 10.3% is made considering the mean of fake news. This error raises to 28.7% when predicting a single day in the future. Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Manuel Goyanes |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2023 | Characterizing the MasterPrint threat on Android devices with capacitive sensorsabstractFingerprint authentication is being widely adopted in Android smartphones. AI-generated fingerprints (dubbed MasterPrints) have already been proposed, but their real-world feasibility remains unexplored. Indeed, none of Google’s biometric security metrics consider this threat. To overcome this limitation, this paper characterizes the threat in six widespread Android devices. Our results show that it is possible (yet improbable) to unlock smartphones leveraging MasterPrints. We test their effectiveness against both known fingerprints (i.e., those used to create the MasterPrint) and unknown ones. Overall, 40.68% and 5.62% of tests were successful when considering known and unknown fingerprints, respectively. However, each device exhibits dramatically different resistance against MasterPrints. Motorola Moto G5 Plus was compromised in 22.89% of tests with unknown fingerprints. Xiaomi 9 Pro and 11S, as well as Samsung S10e, have also been compromised in > 70% of tests when protected with known fingerprints. It has also been shown that MasterPrints do not generalize well, so the attacker requires local knowledge to succeed. Miguel Peidro-Paredes, José María de Fuentes, Lorena González-Manzano, Miguel Velasco-Gomez |
ARES | 3 |
| 2023 | Cybersecurity in the digital world
Lorena González-Manzano, Marta Beltrán, José María de Fuentes, Gianluca Dini, Cristina Alcaraz |
Future Gener. Comput. Syst. | 1 |
| 2023 | KeyEncoder: A secure and usable EEG-based cryptographic key generation mechanismabstractNowadays, a rapid, easy, and convenient access to our private information is essential to carry out both personal and professional activities. In most cases, this information is sensitive and can be stolen due to its importance and the lack of security protocols. In this study we propose a time–invariant cryptographic key generation mechanism based on electroencephalogram (EEG) signals. We employed Discrete Wavelet Transform and autoencoders to extract the biometric features from the EEG signals. Using these features, we construct a scheme to generate secure seeds that can be used as inputs for secure hash functions and obtain cryptographic keys. The mechanism proposed preserves the privacy of the user, as the cryptographic key is generated for each new EEG signal received, avoiding the need of storing the key, previous EEG signals or any other information. Results show that the proposed mechanism is secure against random attacks, as a 0% of False Acceptance Rate is reported, while generating seeds with an entropy of 0.968 in less than 500 ms. Luis Hernández-Álvarez, Elena Barbierato, Stefano Caputo, José María de Fuentes, Lorena González-Manzano, Luis Hernández Encinas, Lorenzo Mucchi |
Pattern Recognit. Lett. | 5 |
| 2022 | Eye-based keystroke prediction for natural texts - a feasibility analysisabstractThe use of videoconferencing is on the rise after COVID-19, being common to look at the screen and see someone typing. A side-channel attack may be launched to infer the text written from the face image. In this paper, we analyse the feasibility of such an attack, being the first proposal which work with a complete keyset (50 keys) and natural texts. We use different scenarios, lighting conditions and natural texts to increase realism. Our study involves 30 participants, who typed 49,365 keystrokes. We characterize the effect of lighting, gender, age and use of glasses. Our results show that on average 13.71% of keystrokes are revealed without error, and up to 31.8%, 52.5% and 61.2% are guessed with a maximum error of 1, 2 and 3 keys, respectively. José Reverte Cazorla, José María de Fuentes, Lorena González-Manzano |
TrustCom | 3 |
| 2021 | Achieving cybersecurity in blockchain-based systems: A surveyabstractWith the increase in connectivity, the popularization of cloud services, and the rise of the Internet of Things (IoT), decentralized approaches for trust management are gaining momentum. Since blockchain technologies provide a distributed ledger, they are receiving massive attention from the research community in different application fields. However, this technology does not provide with cybersecurity by itself. Thus, this survey aims to provide with a comprehensive review of techniques and elements that have been proposed to achieve cybersecurity in blockchain-based systems. The analysis is intended to target area researchers, cybersecurity specialists and blockchain developers. For this purpose, we analyze 272 papers from 2013 to 2020 and 128 industrial applications. We summarize the lessons learned and identify several matters to foster further research in this area. Mar Gimenez-Aguilar, José María de Fuentes, Lorena González-Manzano, David Arroyo |
Future Gener. Comput. Syst. | 3 |
| 2021 | SmartCAMPP - Smartphone-based continuous authentication leveraging motion sensors with privacy preservationabstractContinuous Authentication (CA) approaches are attracting attention due to the explosion of available sensors from IoT devices such as smartphones. However, a critical privacy concern arises when CA data is outsourced. Data from motion sensors may reveal users’ private issues. Despite the need for CA in smartphones, no previous work has explored how to tackle this matter leveraging motion sensors in a privacy-preserving way. In this work, a mechanism dubbed SmartCAMPP is proposed to achieve CA based on gyroscope and accelerometer data. Format-preserving encryption techniques are applied to privately outsource them. Our results show the suitability of the proposed scheme, featuring 76.85% of accuracy while taking 5.12 ms. of computation for authenticating each user. Interestingly, the use of cryptography does not lead to a significant impact as compared to a non-privacy-preserving mechanism. Luis Hernández-Álvarez, José María de Fuentes, Lorena González-Manzano, Luis Hernández Encinas |
Pattern Recognit. Lett. | 3 |
| 2020 | SmartLED: Smartphone-based covert channels leveraging the notification LEDabstractThe widespread adoption of smartphones make them essential in daily routines. Thus, they can be used to create a covert channel without raising suspicions. To avoid detection, networkless communications are preferred. In this paper, we propose SmartLED, a mechanism to build covert channels leveraging a widely available smartphone feature - its notification LED. The secret is encoded through LED blinks using Manhattan encoding. SmartLED is assessed in real-world indoor and outdoor scenarios, considering different distances up to 5 meters. Our results show that the best performance is achieved in dark settings - 34.8 s. are needed to exfiltrate a 7-byte password to a distance of 1 m. Remarkably, distance does not cause a great impact on effective transmission time and shorter blinks do not lead to substantially greater transmission errors. Lorena González-Manzano, Sergio Bernardez, José María de Fuentes |
TrustCom | 1 |
| 2020 | Impact of injection attacks on sensor-based continuous authentication for smartphonesabstractGiven the relevance of smartphones for accessing personalized services in smart cities, Continuous Authentication (CA) mechanisms are attracting attention to avoid impersonation attacks. Some of them leverage Data Stream Mining (DSM) techniques applied over sensorial information. Injection attacks can undermine the effectiveness of DSM-based CA by fabricating artificial sensorial readings.The goal of this paper is to study the impact of injection attacks in terms of accuracy and immediacy to illustrate the time the adversary remains unnoticed. Two well-known DSM techniques (K-Nearest Neighbours and Hoeffding Adaptive Trees) and three data sources (location, gyroscope and accelerometer) are considered due to their widespread usage Results show that even if the attacker does not previously know anything about the victim, a significant attack surface arises – 1.35 min are needed, in the best case, to detect the attack on gyroscope and accelerometer and 7.27 min on location data. Moreover, we show that the type of sensor at stake and configuration settings may have a dramatic effect on countering this threat. Lorena González-Manzano, Upal Mahbub, José María de Fuentes, Rama Chellappa |
Comput. Commun. | 1 |
| 2019 | Design recommendations for online cybersecurity courses
Lorena González-Manzano, José María de Fuentes |
Comput. Secur. | 1 |
| 2019 | AndrODet: An adaptive Android obfuscation detectorabstractObfuscation techniques modify an app’s source (or machine) code in order to make it more difficult to analyze. This is typically applied to protect intellectual property in benign apps, or to hinder the process of extracting actionable information in the case malware. Since malware analysis often requires considerable resource investment, detecting the particular obfuscation technique used may contribute to apply the right analysis tools, thus leading to some savings. In this paper, we propose AndrODet , a mechanism to detect three popular types of obfuscation in Android applications, namely identifier renaming, string encryption, and control flow obfuscation. AndrODet leverages online learning techniques, thus being suitable for resource-limited environments that need to operate in a continuous manner. We compare our results with a batch learning algorithm using a dataset of 34,962 apps from both malware and benign apps. Experimental results show that online learning approaches are not only able to compete with batch learning methods in terms of accuracy, but they also save significant amount of time and computational resources. Particularly, AndrODet achieves an accuracy of 92.02% for identifier renaming detection, 81.41% for string encryption detection, and 68.32% for control flow obfuscation detection, on average. Also, the overall accuracy of the system when apps might be obfuscated with more than one technique is around 80.66%. Omid Mirzaei, José María de Fuentes, Juan Tapiador, Lorena González-Manzano |
Future Gener. Comput. Syst. | 4 |
| 2019 | Editorial: Security and Privacy in Internet of Things
José María de Fuentes, Lorena González-Manzano, Javier López 0001, Pedro Peris-Lopez, Kim-Kwang Raymond Choo |
Mob. Networks Appl. | 2 |
| 2018 | Effect of attacker characterization in ECG-based continuous authentication mechanisms for Internet of Things
Pedro Peris-Lopez, Lorena González-Manzano, Carmen Camara, José María de Fuentes |
Future Gener. Comput. Syst. | 2 |
| 2017 | PRACIS: Privacy-preserving and aggregatable cybersecurity information sharing
José María de Fuentes, Lorena González-Manzano, Juan Tapiador, Pedro Peris-Lopez |
Comput. Secur. | 2 |
| 2017 | Encryption by Heart (EbH) - Using ECG for time-invariant symmetric key generation
Lorena González-Manzano, José María de Fuentes, Pedro Peris-Lopez, Carmen Camara |
Future Gener. Comput. Syst. | 1 |
| 2017 | Assessment of attribute-based credentials for privacy-preserving road traffic services in smart citiesabstractSmart cities involve the provision of advanced services for road traffic users. Vehicular ad hoc networks (VANETs) are a promising communication technology in this regard. Preservation of privacy is crucial in these services to foster their acceptance. Previous approaches have mainly focused on PKI-based or ID-based cryptography. However, these works have not fully addressed the minimum information disclosure principle. Thus, questions such as how to prove that a driver is a neighbour of a given zone, without actually disclosing his identity or real address, remain unaddressed. A set of techniques, referred to as Attribute-Based Credentials (ABCs), have been proposed to address this need in traditional computation scenarios. In this paper, we explore the use of ABCs in the vehicular context. For this purpose, we focus on a set of use cases from European Telecommunications Standards Institute (ETSI) Basic Set of Applications, specially appropriate for the early development of smart cities. We assess which ABC techniques are suitable for this scenario, focusing on three representative ones—Idemix, U-Prove and VANET-updated Persiano systems. Our experimental results show that they are feasible in VANETs considering state-of-the-art technologies, and that Idemix is the most promising technique for most of the considered use cases. José María de Fuentes, Lorena González-Manzano, Jetzabel Serna-Olvera, Fatbardh Veseli |
Pers. Ubiquitous Comput. | 2 |
| 2016 | ase-PoW: A Proof of Ownership Mechanism for Cloud Deduplication in Hierarchical Environments
Lorena González-Manzano, José María de Fuentes, Kim-Kwang Raymond Choo |
SecureComm | 1 |
| 2016 | Implementing a privacy-enhanced attribute-based credential system for online social networks with co-ownership managementabstractOnline social network (OSN) users are exhibiting an increased privacy‐protective behaviour especially since multimedia sharing has emerged as a popular activity over most OSN sites. Popular OSN applications could reveal much of the users’ personal information or let it easily derived, hence favouring different types of misbehaviour. In this article the authors deal with these privacy concerns by applying fine‐grained access control and co‐ownership management over the shared data. This proposal defines access policy as any linear boolean formula that is collectively determined by all users being exposed in that data collection namely the co‐owners. All co‐owners are empowered to take part in the process of data sharing by expressing (secretly) their privacy preferences and, as a result, jointly agreeing on the access policy. Access policies are built upon the concept of secret sharing systems. A number of predicates such as gender, affiliation or postal code can define a particular privacy setting. User attributes are then used as predicate values. In addition, by the deployment of privacy‐enhanced attribute‐based credential technologies, users satisfying the access policy will gain access without disclosing their real identities. The authors have implemented this system as a Facebook application demonstrating its viability, and procuring reasonable performance costs. Esther Palomar, Lorena González-Manzano, Almudena Alcaide, Álvaro Galán |
IET Inf. Secur. | 2 |
| 2016 | PAgIoT - Privacy-preserving Aggregation protocol for Internet of Things
Lorena González-Manzano, José María de Fuentes, Sergio Pastrana, Pedro Peris-Lopez, Luis Hernández Encinas |
J. Netw. Comput. Appl. | 1 |
| 2015 | An efficient confidentiality-preserving Proof of Ownership for deduplication
Lorena González-Manzano, Agustín Orfila |
J. Netw. Comput. Appl. | 1 |
| 2014 | CooPeD: Co-owned Personal Data management
Lorena González-Manzano, Ana I. González-Tablas, José María de Fuentes, Arturo Ribagorda |
Comput. Secur. | 1 |
| 2014 | SoNeUCONABC, an expressive usage control model for Web-Based Social Networks
Lorena González-Manzano, Ana I. González-Tablas, José María de Fuentes, Arturo Ribagorda |
Comput. Secur. | 1 |
| 2014 | Extended U+F Social Network Protocol: Interoperability, reusability, data protection and indirect relationships in Web Based Social Networks
Lorena González-Manzano, Ana I. González-Tablas, José María de Fuentes, Arturo Ribagorda |
J. Syst. Softw. | 1 |
| 2013 | WEVAN - A mechanism for evidence creation and verification in VANETs
José María de Fuentes, Lorena González-Manzano, Ana I. González-Tablas, Jorge Blasco Alís |
J. Syst. Archit. | 2 |
| 2012 | U+F Social Network Protocol: Achieving Interoperability and Reusability between Web Based Social NetworksabstractAlong the time many Web Based Social Networks (WBSNs) have appeared, but not all of them offer the same services. Users may use multiple WBSNs to satisfy their requirements. Besides, operations such as the creation of accounts or the establishment of groups, are repeated in all of them, being a tedious issue. To address this matter, this paper proposes a protocol, based on the UMA core protocol and the FOAF project, to attain interoperability and reusability of resources, identity data and access control policies across different WBSNs. Moreover, an evaluation and a security analysis are presented. Lorena González-Manzano, Ana I. González-Tablas, José María de Fuentes, Arturo Ribagorda |
TrustCom | 1 |