VLDB 2026 Research / reviewers in the wild / expert
Ana Ferreira 0001
dblp:140/5881 · also Ana Margarida Ferreira 0001, Ana Margarida Leite de Almeida Ferreira
· DBLP profile ↗
15ranked-venue papers
8as first author
5since 2021 · last 2026
0000-0002-0953-9411ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 7 · 4 first-author · 3 since 2021Security and privacy · 6 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DRAPEbot: An AI Chatbot Assistant for the DRAPE Platform
Anna Sellani, Francisco Bischoff, Ana Ferreira 0001 |
ICISSP (1) | 3 |
| 2025 | Human-Centered Design for a Usable Privacy SCALE in Healthcare
Catarina Silva 0004, Rita Alves, Isaac Nunes, Joana Pinto, Ana Ferreira 0001 |
CHIRA (3) | 5 |
| 2025 | iSupport-Portugal: Challenges and Insights in Designing a Web Platform for Intervention and Research on Informal Dementia Caregivers
Soraia Teles, Constança Paúl, João Viana, Alberto Freitas, Sara Alves, Óscar Ribeiro, Ana Ferreira 0001 |
ICT4AWE | 7 |
| 2024 | IRIS: A Prototype for GDPR Health Research Compliance
Liliana Ferreira 0003, Teresa Martins, Emanuel Dias, Ana Ferreira 0001 |
CHIRA (2) | 4 |
| 2023 | Attitudes and preferences of digitally skilled dementia caregivers towards online psychoeducation: a cross-sectional studyabstractOnline interventions have been explored to support informal dementia caregivers. Despite favourable evidence on the effectiveness of such interventions, substantial non-use and dropout attrition are reported. This cross-sectional study characterises attitudes and preferences of digitally skilled dementia caregivers (N = 157) towards online psychoeducational interventions (OPIs) and explores associations of attitudes with sociodemographic, context of care, and internet use variables, as well as with previous use of psychosocial interventions, and valorisation of intervention features. Attitudes towards OPIs were moderately positive, but only one-third of caregivers trusted the effectiveness of OPIs. More participants would choose face-to-face (43%) than online interventions (31.4%). The former were seen as more trustworthy and less prone to dropout. Convenience was the most valued intervention feature, and preferences were stated for OPIs with friendly interfaces, free-of-jargon language and allowing to interact with professionals. The multivariable linear regression model suggests that using the internet at least once a week; having ever used a conventional psychosocial intervention; valuing an intervention for its convenience, sessions of short duration, self-personalisation of the plan, and progress self-monitoring, are associated with more favourable attitudes towards OPIs. Findings from this study should inform on the design, targeting and implementation of OPIs for dementia caregivers. Soraia Teles, Ana Ferreira 0001, Constança Paúl |
Behav. Inf. Technol. | 2 |
| 2020 | Patients to Mobilize Their Data: Secure and Flexible mHealth Delegation
Rafael Almeida, Pedro Vieira-Marques, Ana Ferreira 0001 |
ICISSP | 3 |
| 2019 | Accomplishing Transparency within the General Data Protection RegulationabstractTransparency is a user-centric principle proposed to empower users to hold data processors accountable for the usage and the processing of the user’s personal data. Accomplishing transparency may come with some resistance because it requires significant architectural changes, but it is mandatory by law under the recently approved General Data Protection Regulation. To help the transition, we systematically review what Transparency Enhancing Technologies can help to accomplish transparency in agreement with technical requirements that we elicited from the Regulation’s articles. We discuss our findings in the domain of medical data systems, where accomplishing transparency looks particularly controversial due to sensitivity of the personal medical data. Dayana Spagnuelo, Ana Ferreira 0001, Gabriele Lenzini |
ICISSP | 2 |
| 2019 | Persuasion: How phishing emails can influence users and bypass security measures
Ana Ferreira 0001, Soraia Teles |
Int. J. Hum. Comput. Stud. | 1 |
| 2018 | Phishing Through Time: A Ten Year Story based on Abstracts
Ana Ferreira 0001, Pedro Vieira-Marques |
ICISSP | 1 |
| 2016 | Comparing and Integrating Break-the-Glass and Delegation in Role-based Access Control for Healthcareabstractpeer reviewed Ana Ferreira 0001, Gabriele Lenzini |
ICISSP | 1 |
| 2015 | Can Transparency Enhancing Tools Support Patient's Accessing Electronic Health Records?
Ana Ferreira 0001, Gabriele Lenzini |
WorldCIST (1) | 1 |
| 2011 | Usable access control policy and model for healthcareabstractAccess control defines what users can perform within a system. It is usually defined by software engineers and end users are seldom asked for cooperation. The main objective of this paper is to gather the necessary knowledge from the end users of an Electronic Medical Record (EMR) regarding access control and, with their collaboration, define a list of usable access control rules and access control model, which are closer to user needs and workflows. Access control standards in healthcare were also analyzed. Afterwards, focus groups were applied to health professionals and several access control rules were extracted from the analysis of all the information that was gathered. The Break The Glass — Role Based Access Control model (BTG-RBAC) was created and includes the generated access control rules, which are closer to users' workflows and needs and can, therefore, improve EMR's usability while reducing some barriers for its effective integration. Ana Ferreira 0001, Ricardo João Cruz Correia, Marta Brito, Luis Filipe Coelho Antunes |
CBMS | 1 |
| 2009 | How to Securely Break into RBAC: The BTG-RBAC ModelabstractAccess control models describe frameworks that dictate how subjects (e.g. users) access resources. In the role-based access control (RBAC) model access to resources is based on the role the user holds within the organization. RBAC is a rigid model where access control decisions have only two output options: grant or deny. break the glass (BTG) policies on the other hand are flexible and allow users to break or override the access controls in a controlled and justifiable manner. The main objective of this paper is to integrate BTG within the NIST/ANSI RBAC model in a transparent and secure way so that it can be adopted generically in any domain where unanticipated or emergency situations may occur. The new proposed model, called BTG-RBAC, provides a third decision option BTG, which grants authorized users permission to break the glass rather than be denied access. This can easily be implemented in any application without major changes to either the application code or the RBAC authorization infrastructure, apart from the decision engine. Finally, in order to validate the model, we discuss how the BTG-RBAC model is being introduced within a Portuguese healthcare institution where the legislation requires that genetic information must be accessed by a restricted group of healthcare professionals. These professionals, advised by the ethical committee, have required and asked for the implementation of the BTG concept in order to comply with the said legislation. Ana Ferreira 0001, David W. Chadwick, Pedro Farinha, Ricardo João Cruz Correia, Gansen Zhao, Rui Chilro, Luis Filipe Coelho Antunes |
ACSAC | 1 |
| 2006 | How to Break Access Control in a Controlled MannerabstractThe Electronic Medical Record (EMR) integrates heterogeneous information within a Healthcare Institution stressing the need for security and access control. The Biostatistics and Medical Informatics Department from Porto Faculty of Medicine has recently implemented a Virtual EMR (VEMR) in order to integrate patient information and clinical reports within a university hospital. With more than 500 medical doctors using the system on a daily basis, an access control policy and model were implemented. However, the healthcare environment has unanticipated situations (i.e. emergency situations) where access to information is essential. Most traditional policies do not allow for overriding. A policy that allows for "Break-The-Glass (BTG)" was implemented in order to override access control whilst providing for non-repudiation mechanisms for its usage. The policy was easily integrated within the model confirming its modularity and the fact that user intervention in defining security procedures is crucial to its successful implementation and use. Ana Ferreira 0001, Ricardo João Cruz Correia, Luis Filipe Coelho Antunes, Pedro Farinha, E. Oliveira-Palhares, David W. Chadwick, Altamiro da Costa Pereira |
CBMS | 1 |
| 2004 | Integrity for Electronic Patient Record ReportsabstractThe use of an EPR within a hospital is essential in order to integrate and centralize patient healthcare information. With the introduction of this technology information security becomes an important issue, moreover when the EPR integrates several exam results and reports that need to be properly stored and managed. The Biostatistics and Medical Informatics Department in Porto's Faculty of Medicine is implementing a centralized electronic patient record, the HSJ.ICU, to integrate several departments' information that comprises mainly electronic reports. The provision for the integrity of these documents is essential. Usually, the users of the system have blind trust in the information they access. The HSJ.ICU is implementing a process that digitally signs reports automatically, and therefore does not interfere with system's usability. It also provides for simple key management with the use of only one public key pair focusing protection in one single point. The digital signature provides real trust in the way it prevents and detects inconsistencies or errors that may affect information integrity. The approach presented in this paper will guarantee that when there is the need to access patient reports, whether now or in 20 years' time, those are still trustable and valid to be integrated within the EPR. Ana Ferreira 0001, Ricardo João Cruz Correia, Luis Filipe Coelho Antunes, Ernesto Palhares, Pedro Vieira-Marques, Altamiro da Costa Pereira |
CBMS | 1 |