Martin Andreoni

dblp:167/9022 · also Martin Andreoni Lopez, Martin Esteban Andreoni Lopez · DBLP profile ↗
← Back
22ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0002-4170-4341ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Differentiable Rendering Powered End-to-End Adversarial Attack Evaluation
Mansi Phute, Matthew Hull, Haoran Wang 0013, Alec Helbling, Shengyun Peng, Willian Tessaro Lunardi, Martin Andreoni, Wenke Lee, Polo Chau
PAKDD (3)7
2026 Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing
abstract
Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks.
Everton de Matos, Hazaa Alameri, Willian Tessaro Lunardi, Martin Andreoni, Eduardo Viegas 0001
WCNC4
2025 SoundBoost: Effective RCA and Attack Detection for UAV via Acoustic Side-Channel
abstract
Unmanned Aerial Vehicles (UAVs), or drones, are emblematic examples of cyber-physical systems where computational components and physical processes integrate to enable autonomous navigation. UAVs rely heavily on sensors such as Inertial Measurement Units (IMU) and Global Positioning System (GPS) for accurate environmental awareness and control. However, the trust placed in these sensors makes UAVs vulnerable to adversarial attacks that compromise the UAV’s operational integrity. While prior work focuses on detecting attacks against specific sensors, there remains a critical gap in performing Root Cause Analysis (RCA) to determine which component failed and why – especially under ambiguous or conflicting sensor reports. To address this gap, we propose SoundBoost, a novel RCA framework that leverages the UAV’s acoustic side-channel (i.e., sound) to diagnose navigation failures and attribute them to specific sensor compromises. While SoundBoost detects attacks by validating GPS and IMU sensor data, it focuses on post-incident diagnosis. SoundBoost conducts post-incident RCA by extracting robust acoustic signatures and using machine learning to cross-validate reported kinematics against physical behavior. We deploy SoundBoost on a UAV and evaluate it under real-world GPS spoofing attacks and synthesized IMU biasing attacks. SoundBoost achieves 100% true positive rate for IMU attacks and over 80% for GPS spoofing, outperforming the state-of-the-art by 21% – demonstrating its effectiveness as a practical forensic tool for sensor attack RCA.
Haoran Wang 0013, Sangdon Park 0001, Yibin Yang 0001, Seulbae Kim, Willian Tessaro Lunardi, Martin Andreoni, Taesoo Kim, Wenke Lee
DSN7
2025 Contrastive Representation Modeling for Anomaly Detection
abstract
Distance-based anomaly detection methods rely on compact in-distribution (ID) embeddings that are well separated from anomalies. However, conventional contrastive learning strategies often struggle to achieve this balance, either promoting excessive variance among inliers or failing to preserve the diversity of outliers. We begin by analyzing the challenges of representation learning for anomaly detection and identify three essential properties for the pretext task: (1) compact clustering of inliers, (2) strong separation between inliers and anomalies, and (3) preservation of diversity among synthetic outliers. Building on this, we propose a contrastive objective that systematically integrates them into the loss design, enabling effective anomaly representation learning without relying on explicit anomaly labels. We extend this framework with a patch-based learning and evaluation strategy specifically designed to improve the detection of localized anomalies in industrial settings. Our approach demonstrates significantly faster convergence and improved performance compared to standard contrastive methods. It matches or surpasses anomaly detection methods on both semantic and industrial benchmarks, including methods that rely on discriminative training or explicit anomaly labels.
Willian Tessaro Lunardi, Abdulrahman Banabila, Dania Herzalla, Martin Andreoni
ECAI4
2025 RenderBender: A Survey on Adversarial Attacks Using Differentiable Rendering
abstract
Differentiable rendering techniques like Gaussian Splatting and Neural Radiance Fields have become powerful tools for generating high-fidelity models of 3D objects and scenes. Their ability to produce both physically plausible and differentiable models of scenes are key ingredient needed to produce physically plausible adversarial attacks on DNNs. However, the adversarial machine learning community has yet to fully explore these capabilities, partly due to differing attack goals (e.g., misclassification, misdetection) and a wide range of possible scene manipulations used to achieve them (e.g., alter texture, mesh). This survey contributes a framework that unifies diverse goals and tasks, facilitating easy comparison of existing work, identifying research gaps, and highlighting future directions—ranging from expanding attack goals and tasks to account for new modalities, state-of-the-art models, tools, and pipelines, to underscoring the importance of studying real-world threats in complex scenes.
Matthew Hull, Haoran Wang 0013, Matthew Lau, Alec Helbling, Mansi Phute, Chao Zhang 0014, Zsolt Kira, Willian Tessaro Lunardi, Martin Andreoni, Wenke Lee, Polo Chau
IJCAI9
2025 Secure Safety Filter: Towards Safe Flight Control under Sensor Attacks
abstract
Modern autopilot systems are prone to sensor attacks that can jeopardize flight safety. To mitigate this risk, we proposed a modular solution: the secure safety filter, which extends the well-established control barrier function (CBF)-based safety filter to account for, and mitigate, sensor attacks. This module consists of a secure state reconstructor (which generates plausible states) and a safety filter (which computes the safe control input that is closest to the nominal one). Differing from existing work focusing on linear, noise-free systems, the proposed secure safety filter handles bounded measurement noise and, by leveraging reduced-order model techniques, is applicable to the nonlinear dynamics of drones. Software-in-the-loop simulations and drone hardware experiments demonstrate the effectiveness of the secure safety filter in rendering the system safe in the presence of sensor attacks.
Xiao Tan 0002, Junior Sundar, Renzo Bruzzone, Pio Ong, Willian Tessaro Lunardi, Martin Andreoni, Paulo Tabuada, Aaron D. Ames
IROS6
2025 Graph Neural Networks for Jamming Source Localization
Dania Herzalla, Willian Tessaro Lunardi, Martin Andreoni
ECML/PKDD (8)3
2025 Guest Editorial: Special Issue on Zero Trust for Next-Generation Networking
Moayad Aloqaily, Qian Zhang 0001, Martin Andreoni, Michele Nogueira Lima, Xiaojiang Du, Ang Chen 0001
IEEE J. Sel. Areas Commun.3
2024 Workshop: Lightweight Fault Detection in UAVs: A Machine Learning Approach with Dynamic Time Windows
Saeed Alseiari, Willian Tessaro Lunardi, Martin Andreoni
EWSN3
2024 Optimizing feature selection in intrusion detection systems: Pareto dominance set approaches with mutual information and linear correlation
Guilherme N. N. Barbosa, Martin Andreoni, Diogo M. F. Mattos
Ad Hoc Networks2
2023 An Empirical Analysis of MeshShield: a Network Security System for Fully Distributed Networks
Selina Shrestha, Willian Tessaro Lunardi, Martin Andreoni
EWSN3
2023 Exploiting Engineered IQ Samples for Physical Layer Authentication
abstract
This paper proposes a physical layer-based authentication scheme that exploits multiple features from the RF-front-end for wireless mesh networks. Specifically, we engineer the in-phase and quadrature-phase (IQ) samples of the legitimate nodes by generating specific ranges of carrier frequency offset (CFO), phase offset (PO), and DC offset (DCO). This engineered IQ governs all multiple legitimate node transmissions (to cover the entire ranges of CFO, PO, and DCO) and follows a specific probability mass function (PMF). We then obtain an optimal function based on the MSE criterion that closely fits the engineered IQ data, which serves as a reference for authenticating network nodes. In the authentication phase, the optimal function obtained from the IQ data transmissions of the respective node requesting authentication is compared with the optimal reference function. Successful authentication occurs when the difference between the optimal function and reference optimal function falls within predefined thresholds of absolute difference, MSE, and correlation coefficient parameters. Specifically, a node is deemed legitimate only when all three criteria meet the threshold requirements. The node undergoes a second authentication check if only one or two criteria are met. Otherwise, it is marked as a possible intruder. We generated extensive I and Q datasets following the IEEE 802.11 standard waveform to validate the proposed scheme, and the necessary metrics were evaluated. The results showed that instead of being used individually when the underlying criteria of MSE, correlation coefficient, and absolute difference are used together can guarantee better authentication, detection, and false detection rates. The findings indicate that the proposed approach attains a 100% authentication rate at a 5 × 10–2threshold MSE, which represents a 20% improvement over the individual use of MSE.
Hossien B. Eldeeb, Anshul Pandey, Martin Andreoni, Sami Muhaidat
VTC Fall3
2023 ARCADE: Adversarially Regularized Convolutional Autoencoder for Network Anomaly Detection
abstract
As the number of heterogenous IP-connected devices and traffic volume increase, so does the potential for security breaches. The undetected exploitation of these breaches can bring severe cybersecurity and privacy risks. Anomaly-based Intrusion Detection Systems (IDSs) play an essential role in network security. In this paper, we present a practical unsupervised anomaly-based deep learning detection system called ARCADE (Adversarially Regularized Convolutional Autoencoder for unsupervised network anomaly DEtection). With a convolutional Autoencoder (AE), ARCADE automatically builds a profile of the normal traffic using a subset of raw bytes of a few initial packets of network flows so that potential network anomalies and intrusions can be efficiently detected before they cause more damage to the network. ARCADE is trained exclusively on normal traffic. An adversarial training strategy is proposed to regularize and decrease the AE’s capabilities to reconstruct network flows that are out-of-the-normal distribution, thereby improving its anomaly detection capabilities. The proposed approach is more effective than state-of-the-art deep learning approaches for network anomaly detection. Even when examining only two initial packets of a network flow, ARCADE can effectively detect malware infection and network attacks. ARCADE presents 20 times fewer parameters than baselines, achieving significantly faster detection speed and reaction time.
Willian Tessaro Lunardi, Martin Andreoni, Jean-Pierre Giacalone
IEEE Trans. Netw. Serv. Manag.2
2022 Performance Analysis and Evaluation of RF Jamming in IoT Networks
abstract
Jamming attacks, as a form of a denial-of-service attack, significantly degrade the performance of wireless communication systems and can lead to significant overhead in terms of re-transmissions and increased power consumption. In this work, we demonstrate the optimal jamming waveform in internet-of-things (IoT) networks. In particular, we present the analytical bit error rate (BER) of the system under attack by employing two common jamming waveforms: Gaussian noise, and digitally modulated. Then, we validate this analysis with the aid of simulations using the MATLAB WLAN toolbox. Obtained analytical and simulation results, demonstrated system performance degradation under jamming attacks. The simulation results agree with the analytical results in terms of determining the effective jamming waveform. Furthermore, the simulation results depict a 100% PER when the jamming to signal ratio (JSR) is OdB for both QPSK modulated and Gaussian noise waveforms which corroborates with the findings in the literature.
Abubakar S. Ali, Michael Baddeley, Lina Bariah, Martin Andreoni, Willian Tessaro Lunardi, Jean-Pierre Giacalone, Sami Muhaidat
GLOBECOM4
2022 A fast and accurate threat detection and prevention architecture using stream processing
abstract
Summary Late detection of security breaches increases the risk of irreparable damages and limits any mitigation attempts. We propose a fast and accurate threat detection and prevention architecture that combines the advantages of real‐time streaming with batch processing over a historical database. We create a dataset by capturing both legitimate and malicious traffic and propose two ways of combining packets into flows, one considering a time window and the other analyzing the first few packets of each flow per period. We also investigate the effectiveness of our proposal on real‐world network traces obtained from a significant Brazilian network operator providing broadband Internet to their customers. We implement and evaluate three classification algorithms and two anomaly detection methods. The results show an accuracy higher than 95% and an excellent trade‐off between attack detection and false‐positive rates. We further propose an improved scheme based on software defined networks that automatically prevents threats by analyzing only the first few packets of a flow. The proposal promptly and efficiently blocks threats, is robust, and can scale up, even when the attacker employs spoofed IP.
Antonio G. P. Lobato, Martin Andreoni, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle
Concurr. Comput. Pract. Exp.2
2021 Towards Secure Wireless Mesh Networks for UAV Swarm Connectivity: Current Threats, Research, and Opportunities
abstract
UAVs are increasingly appearing in swarms or formations to leverage cooperative behavior, forming flying ad hoc networks. These UAV-enabled networks can meet several complex mission requirements and are seen as a potential enabler for many of the emerging use-cases in future communication networks. Such networks, however, are characterized by a highly dynamic and mobile environment with no guarantee of a central network infrastructure which can cause both connectivity and security issues. While wireless mesh networks are envisioned as a solution for such scenarios, these networks come with their own challenges and security vulnerabilities. In this paper, we analyze the key security and resilience issues resulting from the application of wireless mesh networks within UAV swarms. Specifically, we highlight the main challenges of applying current mesh technologies within the domain of UAV swarms and expose existing vulnerabilities across the communication stack. Based on this analysis, we present a security-focused architecture for UAV mesh communications. Finally, from the identification of these vulnerabilities, we discuss research opportunities posed by the unique challenges of UAV swarm connectivity.
Martin Andreoni, Michael Baddeley, Willian Tessaro Lunardi, Anshul Pandey, Jean-Pierre Giacalone
DCOSS1
2021 An Entropy-based Hybrid Mechanism for Large-Scale Wireless Network Traffic Prediction
abstract
The rising of the Internet of Things (IoT) applications fosters the exponential increase of smart devices, expanding the Internet’s attacking surface. Anomaly prediction mechanisms are mandatory to anticipate security threats. Besides, traffic monitoring and prediction models deliver more resilient and efficient network services. This paper proposes a lightweight user-behavior prediction mechanism based on the decomposition of the network traffic features’ entropy through Discrete Wavelet Transform (DWT) applied to network-flow Shannon Entropy’s time series. The DWT decomposes the entropy into linear and nonlinear components. We compare two forecasting models using Long Short Term Memory (LSTM) Networks and Auto-Regressive Integrated Moving Averages (ARIMA). We evaluate our mechanism in a large-scale academic wireless network, with more than 500 access points. LSTM performs up to 10 times better than ARIMA for predicting the real value of nonlinear flow-source entropy. Considering the transport protocol entropy, LSTM is up to 8 times better than ARIMA, and our results show a high entropy value. LSTM also outperforms ARIMA concerning the prediction time, which is 42% lower for LSTM’s worst-case training time than ARIMA’s best-case training time.
Guilherme N. N. Barbosa, Martin Andreoni, Dianne S. V. Medeiros, Diogo M. F. Mattos
ISNCC2
2020 A Lightweight Network-based Android Malware Detection System
Igor Jochem Sanz, Martin Andreoni, Eduardo Viegas 0001, Vinicius Rodrigues Sanches
Networking2
2019 Toward a monitoring and threat detection system based on stream processing as a virtual network function for big data
abstract
Summary The late detection of security threats causes a significant increase in the risk of irreparable damages and restricts any defense attempt. In this paper, we propose a sCAlable TRAffic Classifier and Analyzer (CATRACA). CATRACA works as an efficient online Intrusion Detection and Prevention System implemented as a Virtualized Network Function. CATRACA is based on Apache Spark, a Big Data Streaming processing system, and it is deployed over the Open Platform for Network Functions Virtualization (OPNFV), providing an accurate real‐time threat‐detection service. The system presents a friendly graphical interface that provides real‐time visualization of the traffic and the attacks that occur in the network. Our prototype can differentiate normal traffic from denial of service (DoS) attacks and vulnerability probes over 95% accuracy under three different datasets. Moreover, CATRACA handles streaming data under concept drift detection with more than 85% of accuracy.
Martin Andreoni, Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle
Concurr. Comput. Pract. Exp.1
2018 An Adaptive Real-Time Architecture for Zero-Day Threat Detection
abstract
Attackers create new threats and constantly change their behavior to mislead security systems. In this paper, we propose an adaptive threat detection architecture that trains its detection models in real time. The major contributions of the proposed architecture are: i) gather data about zero-day attacks and attacker behavior using honeypots in the network; ii) process data in real time and achieve high processing throughput through detection schemes implemented with stream processing technology; iii) use of two real datasets to evaluate our detection schemes, the first from a major network operator in Brazil and the other created in our lab; iv) design and development of adaptive detection schemes including both online trained supervised classification schemes that update their parameters in real time and learn zero-day threats from the honeypots, and online trained unsupervised anomaly detection schemes that model legitimate user behavior and adapt to changes. The performance evaluation results show that proposed architecture maintains an excellent trade-off between threat detection and false positive rates and achieves high classification accuracy of more than 90%, even with legitimate behavior changes and zero-day threats.
Antonio G. P. Lobato, Martin Andreoni, Igor Jochem Sanz, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle
ICC2
2016 A Performance Comparison of Open-Source Stream Processing Platforms
abstract
Distributed stream processing platforms is a new class of real-time monitoring systems that analyze and extracts knowledge from large continuous streams of data. This type of systems is crucial for providing high throughput and low latency required by Big Data or Internet of Things monitoring applications. This paper describes and analyzes three main open-source distributed stream- processing platforms: Storm Flink, and Spark Streaming. We analyze the system architectures and we compare their main features. We carry out two experiments concerning anomaly detection on network traffic to evaluate the throughput efficiency and the resilience to node failures. Results show that the performance of native stream processing systems, Storm and Flink, is up to 15 times higher than the micro-batch processing system, Spark Streaming. On the other hand, Spark Streaming is more robust to node failures and provides recovery without losses.
Martin Andreoni, Antonio G. P. Lobato, Otto Carlos M. B. Duarte
GLOBECOM1
2015 Providing elasticity to intrusion detection systems in virtualized Software Defined Networks
abstract
This paper presents BroFlow, an Intrusion Detection and Prevention System based on Bro traffic analyzer, and on the global network-view feature of OpenFlow Application Programming Interface. BroFlow main contributions are: i) dynamic and elastic resource provision of machines under demand; ii) real-time detection of DoS attacks through simple algorithms implemented in a policy language for network events; iii) immediate reaction to DoS attacks and malicious packets, dropping flows close from their source; iv) strategic sensor positioning for attack detection in the network infrastructure shared by multi-tenants. A system prototype was developed and evaluated in the virtual environment Future Testbed Internet with Security (FITS). An evaluation of the system under attack shows that BroFlow guarantees the forwarding of legitimate packets at the maximal link rate, up to 90% reduction of the maximal network delay caused by the attack, and 50% of bandwidth gain compared with conventional firewalls approaches, even when the attackers are legitimate tenants acting in collusion.
Martin Andreoni, Otto Carlos M. B. Duarte
ICC1