VLDB 2026 Research / reviewers in the wild / expert
Euclides Carlos Pinto Neto
dblp:177/2522 · also Euclides C. Pinto Neto, Euclides Pinto Neto
· DBLP profile ↗
9ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0002-1241-6391ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CloudAPT: A Provenance-Based Dataset for Evaluating APT Countermeasures in Cloud EnvironmentsabstractThe dynamic nature of cloud environments has amplified the challenges of defending against Advanced Persistent Threats (APTs), which exploit the complexity and interconnectedness of modern infrastructures. Existing datasets fail to adequately address the unique requirements of cloud-native systems, particularly those leveraging system provenance graphs for comprehensive analysis. In this work, we present CloudAPT, the first dataset to utilize system provenance graphs for capturing APT behaviors in Kubernetes-based cloud environments. The dataset spans eight days, encompassing the complete APT lifecycle: reconnaissance, initial compromise, privilege escalation, lateral movement, data exfiltration, and covering tracks, while integrating realistic, human-driven user interactions. By centralizing activities on a single worker VM, the dataset ensures granular and transparent data collection, avoiding fragmentation and providing a holistic view of attacker strategies and system responses. CloudAPT includes provenance graph data, cluster logs, and application-level data, offering deep insights into interactions within cloud-native systems. This dataset serves as a foundational resource for developing and benchmarking advanced detection mechanisms and security solutions tailored specifically to the complexities of cloud environments. Md Ariful Haque, Euclides Carlos Pinto Neto, Thomas Pasquier, Shahrear Iqbal |
ISNCC | 2 |
| 2025 | Integrating Auxiliary Knowledge into Machine Learning to Improve the Detection of CyberattacksabstractMalicious activities are becoming more complex and difficult to detect, leading to a need for advanced solutions. Machine Learning (ML) presents several success cases across multiple industries and in cybersecurity, ML has demonstrated promising performance in the detection and classification of malicious activities. However, there are still critical limitations that prevent their wide adoption in cybersecurity operations (e.g., lack of interpretability and too many false positives). KnowledgeInfused Learning (KIL) has the potential to address current limitations through different techniques. One possible approach relies on the adoption of Auxiliary Knowledge (AK), which uses domain knowledge to extract and engineer new features present in the raw data and provides additional context that helps the model better understand and differentiate between legitimate and malicious data. The main goal of this research is to propose a method that uses Auxiliary Knowledge (AK) to improve ML performance in detecting cyberattacks. We leveraged relevant domain knowledge to generate features from the raw data that are difficult for an ML model to discover. This approach also reduces the dependence on large amount of training data (big data) that is necessary for better ML predictions. The experiments used the CICIoT2023 dataset and demonstrated that auxiliary knowledge improves the detection performance, paving the way for future integration of automated knowledge management approaches. Shahrear Iqbal, Sourena Khanzadeh, Euclides Carlos Pinto Neto, Scott Buffett, Madeena Sultana, Adrian Taylor |
ISNCC | 3 |
| 2025 | Cyber Threat Mitigation with Knowledge-Infused Reinforcement Learning and LLM-Guided PoliciesabstractAs cyber threats continue to evolve, there is a need for autonomous cyber defense (ACD) strategies capable of fast and context-aware responses. Reinforcement learning (RL) has shown promise for automating cyber defense by exploring and learning effective countermeasures, yet it often struggles with sparse reward signals and insufficient context to handle diverse attack scenarios. Furthermore, the convergence time taken by an RL agent is often high, which makes it difficult to train the RL agent in online settings. To address these challenges, we propose a large language model (LLM)-enhanced RL method that builds and queries a knowledge graph (KG) derived from agent-environment interactions. We leverage the pre-trained knowledge of an LLM on different cybersecurity frameworks and use the LLM to analyze a part of the KG to generate appropriate actions for the RL agent. We infuse the knowledge extracted from the LLM into the RL agent’s training loop in two ways. First, the state vector of the RL agent is augmented with the most effective action and its corresponding reward, as determined from the KG. Second, the suggested action from the LLM is used as a reference policy. In addition, we introduce a regularization term in the loss function to make the RL policy close to the reference policy. To validate our approach, we develop a custom RL environment guided by the MITRE ATT&CK framework, enabling the agent to generate tailored mitigation strategies for detected cyber attacks. Experimental results show that our proposed approach significantly outperforms the baseline RL by over $75 \%$ in terms of taking better mitigation actions. Md. Shamim Towhid, Shahrear Iqbal, Euclides Carlos Pinto Neto, Nashid Shahriar, Scott Buffett, Madeena Sultana, Adrian Taylor |
PST | 3 |
| 2024 | A review of Machine Learning (ML)-based IoT security in healthcare: A dataset perspective
Euclides Carlos Pinto Neto, Sajjad Dadkhah, Somayeh Sadeghi, Heather Molyneaux, Ali A. Ghorbani 0001 |
Comput. Commun. | 1 |
| 2024 | IoT-PRIDS: Leveraging packet representations for intrusion detection in IoT networksabstractThe Internet of Things (IoT) devices have been integrated into almost all everyday applications of human life such as healthcare, transportation and agriculture. This widespread adoption of IoT has opened a large threat landscape to computer networks, leaving security gaps in IoT-enabled networks. These resource-constrained devices lack sufficient security mechanisms and become the weakest link in our in computer networks and jeopardize systems and data. To address this issue, Intrusion Detection Systems (IDS) have been proposed as one of many tools to mitigate IoT related intrusions. While IDS have proven to be a crucial tools for threat detection, their dependence on labeled data and their high computational costs have become obstacles to real life adoption. In this work, we present IoT-PRIDS, a new framework equipped with a host-based anomaly-based intrusion detection system that leverages “packet representations” to understand the typical behavior of devices, focusing on their communications, services, and packet header values. It is a lightweight non-ML model that relies solely on benign network traffic for intrusion detection and offers a practical way for securing IoT environments. Our results show that this model can detect the majority of abnormal flows while keeping false alarms at a minimum and is promising to be used in real-world applications. Alireza Zohourian, Sajjad Dadkhah, Heather Molyneaux, Euclides Carlos Pinto Neto, Ali A. Ghorbani 0001 |
Comput. Secur. | 4 |
| 2024 | Transferability of Machine Learning Algorithm for IoT Device Profiling and IdentificationabstractThe lack of appropriate cyber security measures deployed on Internet of Things (IoT) makes these devices prone to security issues. Consequently, the timely identification and detection of these compromised devices become crucial. Machine learning (ML) models which are used to monitor devices in a network have made tremendous strides. However, most of the research in profiling and identification uses the same data for training and testing. Hence, a slight change in the data renders most learning algorithms to work poorly. In this article, we study a transferability approach based on the concept of transductive transfer learning for IoT device profiling and identification. Notably, this type of transfer learning works by explicitly assigning labels to the test data in the target domain by using the test feature space in the target domain, with training data from the source domain. Specifically, we propose a three-component system comprising: 1) the device type identification; 2) the vulnerability assessment; and 3) the visualization module. The device type identification component uses the underlying concept of transductive transfer learning where the trained model is transferred to a remote lab for testing. A variety of ML models are evaluated with respect to accuracy, precision, recall, and F1-score in order to determine which are the most suitable for the proposed transferability profiling. Furthermore, the vulnerability of the predicted device type is also assessed by using three vulnerability databases: 1) Vulners; 2) National Vulnerability Database (NVD); and 3) IBM X-Force. Finally, the results from the vulnerability assessment are visualized and displayed on a dashboard. Priscilla Kyei Danso, Sajjad Dadkhah, Euclides Carlos Pinto Neto, Alireza Zohourian, Heather Molyneaux, Rongxing Lu, Ali A. Ghorbani 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Collaborative DDoS Detection in Distributed Multi-Tenant IoT using Federated LearningabstractNowadays, the Internet of Things (IoT) has attracted much attention from the industry, and new initiatives are expected to be developed in the next decade. IoT is establishing a globally connected sensor network in which many devices are connected to the Internet generating large amounts of data. Conversely, many challenges need to be overcome to enable efficient and secure IoT applications (e.g., interoperability, security, standards, and server technologies). Furthermore, edge computing presents a paramount role in the diverse range of IoT applications. In this sense, processing sensitive data for different tenants (e.g., e-health and smart cities applications) requires transactions to be protected and isolated from different flows. Thereupon, different tenants can be targeted by Distributed Denial of Service (DDoS) attacks. However, attacks performed against a tenant remain unknown to others, preventing the improvement of detection and mitigation capabilities for DDoS attacks. The main obstacle in this collaboration relies on maintaining privacy in a multi-tenant environment while sharing the characteristics of attacks faced in the past. In this paper, we propose a collaborative DDoS detection and classification approach for distributed multi-tenant IoT environments using Federated Learning. This approach enables multiples tenants to collaboratively enhance their DDoS detection and classification capabilities across all edge nodes while maintaining their privacy. To accomplish this, tenants train deep learning instances on locally scaled traffic data and share the model parameters with other tenants. This strategy enables safer IoT operations and can be adopted in different applications. The experiments performed on a simulated environment considered the CICD-DoS2019 dataset and showed that the proposed approach can classify different DDoS attacks types with over 84.2% accuracy. The results demonstrate that collaborative DDoS detection enhances tenant protection compared to single detection. Euclides Carlos Pinto Neto, Sajjad Dadkhah, Ali A. Ghorbani 0001 |
PST | 1 |
| 2022 | A Trajectory Evaluation Platform for Urban Air Mobility (UAM)abstractNowadays, there is an increase in the demand for optimized services in urban environments. However, ground transportation in big urban centers has been facing challenges for many years (e.g., resilience and congestion) and new paradigms have been proposed, such as the Urban Air Mobility (UAM) concept. UAM aims to enhance the urban transportation system using manned and unmanned aerial vehicles (i.e., Electric Vertical Takeoff and Landing - eVTOL - vehicles). Although UAM offers many benefits (e.g., cost reduction and increase in transportation capacity), many challenges need to be faced to enable safe and efficient operations. Furthermore, trajectory planning is challenging in the National Airspace System (NAS) and UAM operations due to several factors. Finally, new initiatives concerning UAM trajectory planning can be accelerated with the support of an automatic what-if platform capable of evaluating trajectories feasibility and efficiency. This research aims to propose a simulation platform for enabling trajectory evaluation in UAM operations. This platform, named Trajectory-Based Urban Air Mobility Simulator (TUS), focuses on simulating trajectories in the urban aerial environment. TUS enables users to test new UAM algorithms (e.g., flow management strategies, real-time evaluation of maneuvers effectiveness, airspace configurations) and simulate both manned and unmanned vehicles. Furthermore, TUS operation relies on a set of inputs and evaluates the trajectories generated from efficiency and safety perspectives. This process is performed using a Discrete Event Simulation (DES) approach. The experiments performed showed that TUS can perform a realistic evaluation of UAM trajectories and can be effortlessly used to simulate hundreds of scenarios. Euclides Carlos Pinto Neto, Derick Moreira Baum, Jorge Rady de Almeida Jr., João Battista Camargo Junior, Paulo Sérgio Cugnasca |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2017 | An algorithm to optimise the load distribution of fog environmentsabstractInternet of things, a trend of the following years, makes it possible to develop new applications and services as well as creates a huge amount of data to be processed. In order to support this new paradigm, an extension of cloud computing, named Fog Computing, has been developed. Fog computing improves the cloud security, availability and performance by providing a distributed and powerful communication environment with short delay. Therefore, this new paradigm complements the cloud computing. However, the fog faces several issues such as quality of service (QoS) and multi-tenancy optimisation and load balancing. This paper proposes the algorithm called Multi-tenant Load Distribution Algorithm for Fog Environments (MtLDF) to optimise the load balancing in Fogs environments considering specific multi-tenancy requirements (delay and priority). Finally, we present case studies to show the applicability of the proposed algorithm in comparison to a Delay-Driven Load Distribution (DDLD) strategy. Euclides Carlos Pinto Neto, Gustavo Rau de Almeida Callou, Fernando Aires 0001 |
SMC | 1 |