VLDB 2026 Research / reviewers in the wild / expert
Rocío Cabrera Lozoya
dblp:120/4475
· DBLP profile ↗
7ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-8911-7392ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Evaluating and improving the robustness of security attack detectors generated by LLMsabstractAbstract Large Language Models (LLMs) are increasingly used in software development to generate functions, such as attack detectors , that implement security requirements. A key challenge is ensuring the LLMs have enough knowledge to address specific security requirements, such as information about existing attacks. For this, we propose an approach integrating Retrieval Augmented Generation (RAG) and Self-Ranking into the LLM pipeline. RAG enhances the robustness of the output by incorporating external knowledge sources, while the Self-Ranking technique, inspired by the concept of Self-Consistency, generates multiple reasoning paths and creates ranks to select the most robust detector. Our extensive empirical study targets code generated by LLMs to detect two prevalent injection attacks in web security: Cross-Site Scripting (XSS) and SQL injection (SQLi). Results show a significant improvement in detection performance while employing RAG and Self-Ranking, with an increase of up to 71%pt (on average 37%pt) and up to 43%pt (on average 6%pt) in the F2-Score for XSS and SQLi detection, respectively. Samuele Pasini, Jinhan Kim, Tommaso Aiello, Rocío Cabrera Lozoya, Antonino Sabetta, Paolo Tonella |
Empir. Softw. Eng. | 4 |
| 2024 | Detecting Security Fixes in Open-Source Repositories using Static Code AnalyzersabstractThe sources of reliable, code-level information about vulnerabilities that affect open-source software (OSS) are scarce, which hinders a broad adoption of advanced tools that provide code-level detection and assessment of vulnerable OSS dependencies. Therese Fehrer, Rocío Cabrera Lozoya, Antonino Sabetta, Dario Di Nucci, Damian A. Tamburri |
EASE | 2 |
| 2024 | Negative Complement of a Set of Vulnerability-Fixing Commits: Method and DatasetabstractHigh-quality datasets of code-level vulnerability data are essential to training effective machine-learning (ML) models that identify security-relevant commits (i.e. commits that introduce or fix a vulnerability). Some datasets of this sort of this sort do exist, built by mining open-source code repositories; however, they typically contain only positive instances (i.e. security-relevant instances). Therefore, the researchers intending to use such datasets in ML applications are left with the task of obtaining a corresponding set of negative examples (here referred to as the negative complement of the dataset). Rocío Cabrera Lozoya, Antonino Sabetta, Tommaso Aiello |
EASE | 1 |
| 2022 | An Approach to Generate Realistic HTTP Parameters for Application Layer Deception
Merve Sahin, Cédric Hébert, Rocío Cabrera Lozoya |
ACNS | 3 |
| 2021 | Sociocultural Influences for Password Definition: An AI-based Study
Carlos Ocanto Dávila, Rocío Cabrera Lozoya, Slim Trabelsi |
ICISSP | 2 |
| 2020 | Declarative Access Control for Aggregations of Multiple Ownership DataabstractData aggregation operations are popular in domains like data analytics, machine learning and artificial intelligence. However, despite the availability of information, situations like fragmented ownership and legal frameworks hinder data processing, requiring companies to design complex human-driven processes in order to gather, aggregate, and process data in a compliant way. Our proposal addresses this lack of automation with an access control mechanism extending XACML, an access control standard with language and implementation, to regulate operations with multiple data policies. Marco Rosa, Francesco Di Cerbo, Rocío Cabrera Lozoya |
SACMAT | 3 |
| 2013 | Personalization of a cardiac electromechanical model using reduced order unscented Kalman filtering from regional volumes
Stéphanie Marchesseau, Hervé Delingette, Maxime Sermesant, Rocío Cabrera Lozoya, Catalina Tobon-Gomez, Philippe Moireau, Rosa M. Figueras i Ventura, Karim Lekadir, Alfredo Hernández 0001, Mireille Garreau, Erwan Donal, Christophe Leclercq, Simon G. Duckett, Kawal S. Rhode, C. Aldo Rinaldi, Alejandro F. Frangi, Reza Razavi, Dominique Chapelle, Nicholas Ayache |
Medical Image Anal. | 4 |