VLDB 2026 Research / reviewers in the wild / expert
Carolina Fernandez 0001
dblp:153/4120-1 · also Carolina Fernández 0001, Carolina Fernández-Martínez
· DBLP profile ↗
5ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0003-1865-7177ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A knowledge-based multi-agent framework for security control recommendationabstractHardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise. In this regard, Decision Support Systems (DSS) with embedded expert knowledge can assist users by guiding them with security recommendations to meet their objectives. This work proposes a Security DSS that recommends security control sub-families given minimal user requirements indicating coverage of different security dimensions. It leverages a curated, unified dataset from both well-known Information Security (InfoSec) and academic sources. This DSS is defined as a non-zero-sum, simultaneous game that is grounded in a Multi-Agent Influence Diagram (MAID) model and explores the decision space over 7 security dimensions or agents, using no-regret online learning to ultimately find the security control sub-families that best fit the requirements while incurring minimal under- and over-provisioning of security resources. This work was validated in terms of performance and accuracy, among others, for varying dataset sizes. It shows exceptional satisfaction coverage results of 99% when using as little as ∼ 65% of the SW-implementable security controls, running in 1.2–35.7 seconds; and more moderate coverage results of 73%–77% when using ∼ 29% of the controls, resolving in 0.8–13.8 seconds. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
Knowl. Based Syst. | 1 |
| 2025 | A Bayesian Network Approach for Enhancing Security-Focused Decision Support SystemsabstractThe adoption and integration of heterogeneous stacks in most of today’s open-source based networks brings clear benefits like interoperability and availability of advanced features. Yet, on the other hand the increasing number of interconnecting components and moving parts requires maintaining an ever increasing base of interdisciplinary knowledge of different tools in different domains to ensure proper operation. To alleviate such efforts, this work proposes a Decision Support System (DSS) to guide infrastructure operators through the selection of security approaches (e.g. tools) to adopt in their environments. This framework easily captures the end-user high-level requirements on the security triad for different domains and runs inference on the designated models to provide the identified tools (security mechanisms) that better serve such needs. The presented DSS aims at delivering an understandable and extensible framework to accommodate varying requirements and Bayesian Network (BN) models. The architecture and modelling of the system are proposed, aligned with its theoretical framework. Its performance is evaluated in terms of time and prediction accuracy. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
LCN | 1 |
| 2025 | A Vpn-As-A-Service Tailored Enabler for Computing-Constrained EnvironmentsabstractIndustry has embraced Zero Trust (ZT) architectural tenets and implementations for cloud-native environments, following stricter security requirements to both internal and external tenants. Among others, these approaches combine finegrained identity management and monitoring for both inventorying and better analysing the devices' security posture for overall protection, along with strict separation of concerns and isolation to enforce minimal privilege. Networking-wise, ZT approaches rely as well on isolation and least privilege; enacted by separate, secure tunnels per tenant connecting to a given infrastructure. Such implementations can also be applied to the connectivity within and towards experimental infrastructures. In this sense, this work contributes the design and evaluation of a cloud-native VPN-as-a-Service (VPNaaS) that can be (i) easily orchestrated to deploy on-the-fly, separate tunnels per each tenant remotely connecting to the infrastructure; (ii) integrated with common Identity and Access Management (IAM) tools, key to ZT deployments; and (iii) adapt to computing- or entropyconstrained environments. This solution is customisable and allows, among others, to select from RSA or Elliptic Curves (EC) as key generation algorithm and their parameters to achieve more secure keys and adapt to resource-constrained environments. Carolina Fernandez 0001, César Cajas Parra, Muhammad Shuaib Siddiqui |
NetSoft | 1 |
| 2025 | Extending Intent-Powered Network Management with LMs in B5G InfrastructuresabstractDue to their manual, error-prone, and resourceintensive nature, traditional network management methods become unfeasible for highly dynamic, complex, and heterogeneous Beyond 5G (B5G) systems. In this landscape, Intent-Based Networking (IBN) emerges as a promising solution that automates the service lifecycle while offering flexibility and scalability. Nevertheless, IBN faces challenges in expressing, interpreting, and refining high-level intents across diverse Use Cases (UCs). This work proposes a Language Model Intent-based Application Programming Interface (LM-IbAPI) for enhanced dynamic network management in B5G infrastructures to address these challenges. In the framework of the 6GDIFERENTE project, our solution is seamlessly integrated with the management layer to translate multiple intents from diverse UCs into precise network actions with accuracy and reduced time response. We employed Ollama as a unified framework to quickly and effectively test several language models. The results demonstrated that mistral_7B achieved the best trade-off between processing time and accuracy, being capable of generalising across varying numbers of users, services, operators, and South-bound Interfaces (SBIs). Claudia Carballo González, Sergio Giménez Antón, Miquel Tarzan-Lorente, Hatim Chergui, Carolina Fernandez 0001 |
NetSoft | 5 |
| 2017 | SHIELD: A novel NFV-based cybersecurity frameworkabstractSHIELD is an EU-funded project, targeting at the design and development of a novel cybersecurity framework, which offers security-as-a-Service in an evolved telco environment. The SHIELD framework leverages NFV (Network Functions Virtualization) and SDN (Software-Defined Networking) for virtualization and dynamic placement of virtualised security appliances in the network (virtual Network Security Functions - vNSFs), Big Data analytics for real-time incident detection and mitigation, as well as attestation techniques for securing both the infrastructure and the services. This papers discusses key use cases and requirements for the SHIELD framework and presents a high-level architectural approach. Georgios Gardikis, K. Tzoulas, K. Tripolitis, A. Bartzas, Socrates Costicoglou, Antonio Lioy, Bernat Gastón, Carolina Fernandez 0001, Cristian Dávila, Antonis Litke, Antonio Pastor 0001, Jerónimo Núñez, Ludovic Jacquin, Hamza Attak, N. Davri, Georgios Xilouris, M. Kafetzakis, Dimitris Katsianis, Ioannis Neokosmidis, M. Terranova, C. Giustozzi, T. Batista, R. Preto, Eleni Trouva, Y. Angelopoulos, Akis Kourtis |
NetSoft | 8 |