VLDB 2026 Research / reviewers in the wild / expert
Ricardo Mendes
dblp:14/724
· DBLP profile ↗
15ranked-venue papers
6as first author
10since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 6 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Active Attribute Inference Against Well-Generalized Models In Federated LearningabstractFederated Learning (FL), a distributed learning mechanism where data is decentralized across multiple devices and periodic gradient updates are shared, is an alternative to centralized training that aims to address privacy issues arising from raw data sharing. Despite the expected privacy benefits, prior research showcases the potential privacy leakage derived from overfitting, exploited by passive attacks. However, limited attention has been given to understanding and defending against active threats that increase model leakage by interfering with the training process, instead of relying on overfitting. This work addresses this gap by introducing Active Attribute Inference (AAI⋆), a novel active attack that encodes sensitive attribute information by making any targeted training sample leave a distinguishable footprint on the gradient of maliciously modified neurons [8]. Results, using two real-world datasets, show that it is possible to successfully encode sensitive information incurring a small error in terms of neuron activation. More importantly, on a practical scenario, AAI⋆can improve upon a state-of-the-art approach by achieving over 90% of restricted ROC AUC, therefore increasing model leakage. To defend against such active attacks, this work introduces several attack detection strategies tailored for different levels of the defender’s knowledge. Including the novel White-box Attack Detection Mechanism (WADM⋆) that detects abnormal changes in weights distribution, and two black-box strategies based on the monitorization of model performance. Results show that the detection rate can be 100% on both datasets. Remarkably, WADM⋆reduces any attack to random guessing while preserving model utility, offering significant improvements over existing defenses, particularly when clients are non-IID. By proposing active attacks against well-generalized models and effective countermeasures, this research contributes to a better understanding of privacy in FL systems. Catarina Gomes, Ricardo Mendes, João P. Vilela |
EuroS&P | 2 |
| 2024 | Privkit: A Toolkit of Privacy-Preserving Mechanisms for Heterogeneous Data TypesabstractWith the massive data collection from different devices, spanning from mobile devices to all sorts of IoT devices, protecting the privacy of users is a fundamental concern. In order to prevent unwanted disclosures, several Privacy-Preserving Mechanisms (PPMs) have been proposed. Nevertheless, due to the lack of a standardized and universal privacy definition, configuring and evaluating PPMs is quite challenging, requiring knowledge that the average user does not have. In this paper, we propose a privacy toolkit - Privkit - to systematize this process and facilitate automated configuration of PPMs. Privkit enables the assessment of privacy-preserving mechanisms with different configurations, while allowing the quantification of the achieved privacy and utility level of various types of data. Privkit is open source and can be extended with new data types, corresponding PPMs, as well as privacy and utility assessment metrics and privacy attacks over such data. This toolkit is available through a Python Package with several state-of-the-art PPMs already implemented, and also accessible through a Web application. Privkit constitutes a unified toolkit that makes the dissemination of new privacy-preserving methods easier and also facilitates reproducibility of research results, through a repository of Jupyter Notebooks that enable reproduction of research results. Mariana Cunha, Guilherme Duarte 0001, Ricardo Andrade, Ricardo Mendes, João P. Vilela |
CODASPY | 4 |
| 2024 | Exploiting Internal Randomness for Privacy in Vertical Federated Learning
Yulian Sun, Ricardo Mendes, Derui Zhu, Yue Xia, Yong Li 0021, Asja Fischer |
ESORICS (2) | 3 |
| 2024 | Robust Skin Color Driven Privacy-Preserving Face Recognition Via Function Secret SharingabstractIn this work, we leverage the pure skin color patch from the face image as the additional information to train an auxiliary skin color feature extractor and face recognition model in parallel to improve performance of state-of-the-art (SOTA) privacy-preserving face recognition (PPFR) systems. Our solution is robust against black-box attacking and well-established generative adversarial network (GAN) based image restoration. We analyze the potential risk in previous work, where the proposed cosine similarity computation might directly leak the protected precomputed embedding stored on the server side. We propose a Function Secret Sharing (FSS) based face embedding comparison protocol without any intermediate result leakage. In addition, we show in experiments that the proposed protocol is more efficient compared to the Secret Sharing (SS) based protocol. Yufan Jiang, Yong Li 0021, Ricardo Mendes, Joachim Denzler |
ICIP | 4 |
| 2023 | Velocity-Aware Geo-IndistinguishabilityabstractLocation Privacy-Preserving Mechanisms (LPPMs) have been proposed to mitigate the risks of privacy disclosure yielded from location sharing. However, due to the nature of this type of data, spatio-temporal correlations can be leveraged by an adversary to extenuate the protections. Moreover, the application of LPPMs at collection time has been limited due to the difficulty in configuring the parameters and in understanding their impact on the privacy level by the end-user. In this work we adopt the velocity of the user and the frequency of reports as a metric for the correlation between location reports. Based on such metric we propose a generalization of Geo-Indistinguishability denoted Velocity-Aware Geo-Indistinguishability (VA-GI). We define a VA-GI LPPM that provides an automatic and dynamic trade-off between privacy and utility according to the velocity of the user and the frequency of reports. This adaptability can be tuned for general use, by using city or country-wide data, or for specific user profiles, thus warranting fine-grained tuning for users or environments. Our results using vehicular trajectory data show that VA-GI achieves a dynamic trade-off between privacy and utility that outperforms previous works. Additionally, by using a Gaussian distribution as estimation for the distribution of the velocities, we provide a methodology for configuring our proposed LPPM without the need for mobility data. This approach provides the required privacy-utility adaptability while also simplifying its configuration and general application in different contexts. Ricardo Mendes, Mariana Cunha, João P. Vilela |
CODASPY | 1 |
| 2022 | Prediction of Mobile App Privacy Preferences with User Profiles via Federated LearningabstractPermission managers in mobile devices allow users to control permissions requests, by granting of denying application's access to data and sensors. However, existing managers are ineffective at both protecting and warning users of the privacy risks of their permissions' decisions. Recent research proposes privacy protection mechanisms through user profiles to automate privacy decisions, taking personal privacy preferences into consideration. While promising, these proposals usually resort to a centralized server towards training the automation model, thus requiring users to trust this central entity. In this paper we propose a methodology to build privacy profiles and train neural networks for prediction of privacy decisions, while guaranteeing user privacy, even against a centralized server. Specifically, we resort to privacy-preserving clustering techniques towards building the privacy profiles, that is, the server computes the centroids (profiles) without access to the underlying data. Then, using federated learning, the model to predict permission decisions is learnt in a distributed fashion while all data remains locally in the users' devices. Experiments following our methodology show the feasibility of building a personalized and automated permission manager guaranteeing user privacy, while also reaching a performance comparable to the centralized state of the art, with an F1-score of 0.9. André Brandão, Ricardo Mendes, João P. Vilela |
CODASPY | 2 |
| 2022 | Enhancing User Privacy in Mobile Devices Through Prediction of Privacy Preferences
Ricardo Mendes, Mariana Cunha, João P. Vilela, Alastair R. Beresford |
ESORICS (1) | 1 |
| 2022 | Effect of User Expectation on Mobile App Privacy: A Field StudyabstractRuntime permission managers for mobile devices allow requests to be performed at the time in which permissions are required, thus enabling the user to grant/deny requests in context according to their expectations. However, in order to avoid cognitive overload, second and subsequent requests are usually automatically granted without user intervention/awareness. This paper explores whether these automated decisions fit user expectations. We performed a field study with 93 participants to collect their privacy decisions, the surrounding context and whether each request was expected. The collected 65261 permission decisions revealed a strong misalignment between apps’ practices and expectation as almost half of requests are unexpected by users. This ratio strongly varies with the requested permission, the category and visibility of the requesting application and the user itself; that is, expectation is subjective to each individual. Moreover, privacy decisions are most strongly correlated with user expectation, but such correlation is also highly personal. Finally, Android’s default permission manager would have violated the privacy of our participants 15% of the time. Ricardo Mendes, André Brandão, João P. Vilela, Alastair R. Beresford |
PerCom | 1 |
| 2021 | Efficient Privacy Preserving Distributed K-Means for Non-IID Data
André Brandão, Ricardo Mendes, João P. Vilela |
IDA | 2 |
| 2021 | Charon: A Secure Cloud-of-Clouds System for Storing and Sharing Big DataabstractWe presentCharon, a cloud-backed storage system capable of storing and sharing big data in a secure, reliable, and efficient way using multiple cloud providers and storage repositories to comply with the legal requirements of sensitive personal data.Charonimplements three distinguishing features: (1) it does not require trust on any single entity, (2) it does not require any client-managed server, and (3) it efficiently deals with large files over a set of geo-dispersed storage services. Besides that, we developed a novel Byzantine-resilient data-centric leasing protocol to avoid write-write conflicts between clients accessing shared repositories. We evaluateCharonusing micro and application-based benchmarks simulating representative workflows from bioinformatics, a prominent big data domain. The results show that our unique design is not only feasible but also presents an end-to-end performance of up to$2.5\times$2.5×better than other cloud-backed solutions. Ricardo Mendes, Tiago Oliveira 0008, Vinicius Vielmo Cogo, Nuno Neves 0001, Alysson Neves Bessani |
IEEE Trans. Cloud Comput. | 1 |
| 2020 | Impact of Frequency of Location Reports on the Privacy Level of Geo-indistinguishabilityabstractAbstract Location privacy has became an emerging topic due to the pervasiveness of Location-Based Services (LBSs). When sharing location, a certain degree of privacy can be achieved through the use of Location Privacy-Preserving Mechanisms (LPPMs), in where an obfuscated version of the exact user location is reported instead. However, even obfuscated location reports disclose information which poses a risk to privacy. Based on the formal notion of differential privacy, Geo-indistinguishability has been proposed to design LPPMs that limit the amount of information that is disclosed to a potential adversary observing the reports. While promising, this notion considers reports to be independent from each other, thus discarding the potential threat that arises from exploring the correlation between reports. This assumption might hold for the sporadic release of data, however, there is still no formal nor quantitative boundary between sporadic and continuous reports and thus we argue that the consideration of independence is valid depending on the frequency of reports made by the user. This work intends to fill this research gap through a quantitative evaluation of the impact on the privacy level of Geo-indistinguishability under different frequency of reports. Towards this end, state-of-the-art localization attacks and a tracking attack are implemented against a Geo-indistinguishable LPPM under several values of privacy budget and the privacy level is measured along different frequencies of updates using real mobility data. Ricardo Mendes, Mariana Cunha, João P. Vilela |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | On the Effect of Update Frequency on Geo-Indistinguishability of Mobility TracesabstractSharing location data is becoming more popular as mobile devices become ubiquitous. Location-based service providers use this type of data to provide geographically contextualized services to their users. However, sharing exact locations with possibly untrustworthy entities poses a thread to privacy. Geo-indistinguishability has been recently proposed as a formal notion based on the concept of differential privacy to design location privacy-preserving mechanisms in the context of sporadic release of location data. While adaptations for the case of continuous location updates have been proposed, the study on how the frequency of updates impacts the privacy and utility level is yet to be made. In this paper we address this issue, by analyzing the effect of frequency updates on the privacy and utility levels of four mechanisms: the standard planar Laplacian mechanism suitable for sparse locations, and three variants of an adaptive mechanism that is an adaptation of the standard mechanism for continuous location updates. Results show that the frequency of updates largely impacts the correlation between points. As the frequency of updates decreases, the correlation also decreases. The adaptive mechanism is able to adjust the privacy and utility levels accordingly to the correlation between past positions and current position. However, the estimator function that is used to predict the current location has a great influence in the obtained results. Ricardo Mendes, João P. Vilela |
WISEC | 1 |
| 2016 | Exploring Key-Value Stores in Multi-Writer Byzantine-Resilient Register EmulationsabstractResilient register emulation is a fundamental technique to implement dependable storage and distributed systems. In data-centric models, where servers are modeled as fail-prone base objects, classical solutions achieve resilience by using fault-tolerant quorums of read-write registers or read-modify-write objects. Recently, this model has attracted renewed interest due to the popularity of cloud storage providers (e.g., Amazon S3), that can be modeled as key-value stores (KVSs) and combined for providing secure and dependable multi-cloud storage services. In this paper we present three novel wait-free multi-writer multi-reader regular register emulations on top of Byzantine-prone KVSs. We implemented and evaluated these constructions using five existing cloud storage services and show that their performance matches or surpasses existing data-centric register emulations. Tiago Oliveira 0008, Ricardo Mendes, Alysson Neves Bessani |
OPODIS | 2 |
| 2014 | SCFS: A Shared Cloud-backed File System
Alysson Neves Bessani, Ricardo Mendes, Tiago Oliveira 0008, Nuno Neves 0001, Miguel Correia 0001, Marcelo Pasin, Paulo Veríssimo |
USENIX ATC | 2 |
| 2001 | A Framework for Modeling Strategy, Business Processes and Information SystemsabstractIn order to continuously improve its knowledge and to identify problems and possible solutions, an organization requires understanding of the way business is aligned with the organizational strategy and how information systems are supporting the business. The paper presents a framework for describing and associating organizational concepts at multiple levels of detail using three separate areas of concerns: goals and strategy, business processes, and information systems. The framework is presented as an extension to the Unified Modeling Language (UML) using a standard UML Profile. The framework concepts are illustrated by modeling the purchase and sales business operations of a retail store from the strategic, process and information systems viewpoints. André Vasconcelos 0001, Artur Caetano, João Neves 0005, Pedro Sinogas, Ricardo Mendes, José M. Tribolet |
EDOC | 5 |