VLDB 2026 Research / reviewers in the wild / expert
Diogo Barradas
dblp:204/5176
· DBLP profile ↗
24ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0003-0338-2692ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 7 first-author · 15 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Huma: Censorship Circumvention via Web Protocol Tunneling with Deferred Traffic Replacement
Sina Kamali, Diogo Barradas |
NDSS | 2 |
| 2026 | Uncovering robot joint-level controller actions from encrypted network traffic: Empirical attacks and information-theoretic boundsabstractThis study examines the privacy risks associated with the teleoperation of robots controlled via encrypted network communications. From the perspective of a network eavesdropper, we explore the potential to infer sensitive robotic actions by analyzing traffic metadata, such as packet timing, size, and direction. We investigate this threat using a smartphone’s Inertial Measurement Unit (IMU) to control a collaborative robotic arm via three joint-level modalities—position, velocity, and torque—to perform four distinct actions. First, empirical traffic analysis demonstrates that an adversary can identify robot actions with high accuracy using standard machine learning classifiers. Second, to determine whether the remaining classification errors stem from empirical model limitations or the structural constraints of the physical protocols, we apply a classifier-agnostic information-theoretic evaluation. Using mutual information, we derive Bayes optimal accuracy bounds and show that torque control leaks more deterministic information than suggested by empirical models, while velocity inherently exposes less information. Third, by prototyping a traffic padding defense, we evaluate the limitations of standard obfuscation against these structural leakages. Our findings highlight the necessity of information-theoretic bounds in privacy research and inform the design of secure robotic teleoperation APIs. Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
Comput. Secur. | 2 |
| 2025 | On the Feasibility of Fingerprinting Collaborative Robot Network Traffic
Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
ARES (1) | 2 |
| 2025 | TSA-WF: Exploring the Effectiveness of Time Series Analysis for Website Fingerprinting
Michael Wrana, Uzma Maroof, Diogo Barradas |
ARES (1) | 3 |
| 2025 | RevealNet: Distributed Traffic Correlation for Attack Attribution on Programmable NetworksabstractNetwork attackers have increasingly resorted to proxy chains, VPNs, and anonymity networks to conceal their activities. To tackle this issue, past research has explored the use of traffic correlation techniques to perform attack attribution, i.e., to identify an attacker’s true network location. However, current traffic correlation approaches rely on well-provisioned and centralized systems that ingest flows from multiple network probes to compute correlation scores. Unfortunately, this makes correlation efforts scale poorly for large high-speed networks. In this paper, we propose RevealNet, a decentralized framework for attack attribution that orchestrates a fleet of P4programmable switches to perform traffic correlation. We build on top of a set of correlation primitives inspired by prior work on computing and comparing flow sketches-compact summaries of flows’ characteristics-to enable efficient, distributed, in-network traffic correlation. Our evaluation suggests that RevealNet achieves comparable accuracy to centralized attack attribution systems while significantly reducing the computational complexity and bandwidth overheads imposed by correlation tasks. Gurjot Singh, Alim Dhanani, Diogo Barradas |
NCA | 3 |
| 2025 | Uncovering Robot Joint-Level Controller Actions from Encrypted Network Traffic
Diogo Barradas, Urs Hengartner, Yue Hu 0001 |
SEC (1) | 2 |
| 2025 | Anix: Anonymous Blackout-Resistant Microblogging with Message EndorsingabstractRepressive governments are increasingly resorting to Internet shutdowns to control the flow of information during political unrest. In response, messaging apps built on top of mobile-based mesh networks have emerged as important communication tools for citizens and activists. While different flavors of these apps exist, those featuring microblogging functionalities are attractive for swiftly informing and mobilizing individuals. However, most apps fail to simultaneously uphold user anonymity while providing safe ways for users to build trust in others and the messages flowing through the mesh. We introduce Anix, a blackout-resistant app with two novel features: remote trust establishment and anonymous message endorsing. Anix also leverages a set of identity revocation primitives for the fine-grained management of trust relationships and to provide enhanced anonymity. Our evaluation of Anix through comprehensive micro-benchmarks and simulations showcases its practicality and resilience in shutdown scenarios. Sina Kamali, Diogo Barradas |
SP | 2 |
| 2025 | SoK: The Spectre of Surveillance and Censorship in Future Internet ArchitecturesabstractRecent initiatives known as Future Internet Architectures (FIAs) seek to redesign the Internet to improve performance, scalability, and security. However, some governments perceive Internet access as a threat to their political standing and engage in widespread network surveillance and censorship. In this paper, we provide an in-depth analysis of the design principles of prominent FIAs in terms of their packet structure, addressing and naming schemes, and routing protocols to foster discussion on how these new systems interact with censorship and surveillance apparatuses. Further, we assess the extent to which existing surveillance and censorship mechanisms can successfully target FIA users while discussing privacy enhancing technologies to counter these mechanisms. We conclude by providing guidelines for future research into novel FIA-based privacy-enhancing technologies, and recommendations to guide the evaluation of these technologies. Michael Wrana, Diogo Barradas, N. Asokan |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Signalling Load-aware Conditional Handover in 5G Non-Terrestrial NetworksabstractLow Earth orbit (LEO) satellites-based non-terrestrial networks (NTN) are envisioned to complement the fifth-generation (5G) terrestrial networks (TN), enabling global cellular services. However, the high mobility and large coverage of these satellites result in frequent and numerous inter-satellite handovers, leading to signalling storms that degrade the satellite gNodeB services. To address this, we mathematically formulate the handover problem and propose a novel signalling load-aware handover protocol based on conditional handover. We evaluate the effectiveness of the protocol using a customized discrete-event simulator and compare it against a set of baseline conditional handover schemes. Our findings show that the proposed protocol significantly reduces signalling peaks and balances the load more effectively, enhancing the robustness and efficiency of handover in 5G NTN. The simulator is made publicly available. Mohammad Ali Salahuddin 0001, Yunli Wang, Noura Limam, Bo Sun 0004, Diogo Barradas, Raouf Boutaba |
CNSM | 7 |
| 2024 | Secure and Efficient Group Handover Protocol in 5G Non-Terrestrial NetworksabstractThe growing low-Earth orbit (LEO) satellite con-stellations have become an essential part of the fifth-generation (5G) non-terrestrial network (NTN) market. These satellites can enable direct-to-cell connectivity for mobile devices and support various applications with ubiquitous coverage for 5G and beyond networks. However, satellite-based NTNs bring several challenges to the 5G handover protocol design. The high mobility of satellites can lead to signaling storms and security compromises during handovers. This paper addresses these challenges by proposing a secure and efficient group hand over protocol. The protocol's effectiveness is evaluated on a custom discrete-event simulator and compared against the baseline 5G hand over scheme. The simulator is made publicly available. A. Akbariazirani, Mohammad Ali Salahuddin 0001, Diogo Barradas, Noura Limam, Raouf Boutaba |
ICC | 5 |
| 2024 | Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset Sum
Daniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro 0004, Diogo Barradas, Bernardo Portela, João Vinagre, Bernardo Ferreira, Nicolas Christin, Nuno Santos 0001 |
NDSS | 5 |
| 2024 | Extending C2 Traffic Detection Methodologies: From TLS 1.2 to TLS 1.3-enabled MalwareabstractAs the Internet evolves from TLS 1.2 to TLS 1.3, it offers enhanced security against network eavesdropping for online communications. However, this advancement also enables malicious command and control (C2) traffic to more effectively evade malware detectors and intrusion detection systems. Among other capabilities, TLS 1.3 introduces encryption for most handshake messages and conceals the actual TLS record content type, complicating the task for state-of-the-art C2 traffic classifiers that were initially developed for TLS 1.2 traffic. Given the pressing need to accurately detect malicious C2 communications, this paper examines to what extent existing C2 classifiers for TLS 1.2 are less effective when applied to TLS 1.3 traffic, posing a central research question: is it possible to adapt TLS 1.2 detection methodologies for C2 traffic to work with TLS 1.3 flows? Diogo Barradas, Carlos Novo, Bernardo Portela, Sofia Romeiro, Nuno Santos 0001 |
RAID | 1 |
| 2024 | NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgeabstractNetShuffle is a censorship resistance system that offers "shuffle proxies," where regular proxy services (e.g., HTTPS proxies, Tor bridges) are decoupled from their addresses via continuous in-network change. This makes shuffle proxies significantly more difficult to block compared to their traditional counterparts, because the network locations are now in constant flux. NetShuffle is also designed to engage a new class of support base—edge networks—which have received scant attention from existing work. NetShuffle uses emerging programmable switches to provide the shuffle, while staying otherwise transparent to services and clients, enabling it to be applied as a drop-in network appliance to help promote Internet freedom. We have prototyped NetShuffle in testbed environments and operated it seamlessly on a slice of a live campus network for more than a month, showing that it provides network shuffles in a way that is transparent and incurs negligible overheads. Patrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Diogo Barradas, Ang Chen 0001, Micah Sherr, Benjamin E. Ujcich |
SP | 5 |
| 2024 | SpotProxy: Rediscovering the Cloud for Censorship Circumvention
Patrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas, Ang Chen 0001, Micah Sherr, Moti Yung |
USENIX Security Symposium | 4 |
| 2023 | DeepSE-WF: Unified Security Estimation for Website Fingerprinting DefensesabstractWebsite fingerprinting (WF) attacks, usually conducted with the help of a machine learning-based classifier, enable a network eavesdropper to pinpoint which website a user is accessing through the inspection of traffic patterns. These attacks have been shown to succeed even when users browse the Internet through encrypted tunnels, e.g., through Tor or VPNs. To assess the security of new defenses against WF attacks, recent works have proposed feature-dependent theoretical frameworks that estimate the Bayes error of an adversary's features set or the mutual information leaked by manually-crafted features. Unfortunately, as WF attacks increasingly rely on deep learning and latent feature spaces, our experiments show that security estimations based on simpler (and less informative) manually-crafted features can no longer be trusted to assess the potential success of a WF adversary in defeating such defenses. In this work, we propose DeepSE-WF, a novel WF security estimation framework that leverages specialized kNN-based estimators to produce Bayes error and mutual information estimates from learned latent feature spaces, thus bridging the gap between current WF attacks and security estimation methods. Our evaluation reveals that DeepSE-WF produces tighter security estimates than previous frameworks, reducing the required computational resources to output security estimations by one order of magnitude. Alexander Veicht, Cédric Renggli, Diogo Barradas |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | Stegozoa: Enhancing WebRTC Covert Channels with Video Steganography for Internet Censorship CircumventionabstractSeveral totalitarian states around the world deploy sophisticated censorship apparatuses to prevent citizens from freely accessing the Internet. To counter these restrictions, some censorship-circumven-tion tools establish covert channels through the media streams of popular conferencing applications. A recent tool named Protozoa allows for establishing high-performing, peer-to-peer covert channels over WebRTC media streams. However, Protozoa is vulnerable to potential man-in-the-middle attacks. This may occur in cases where WebRTC applications rely on WebRTC gateways to mediate users' connections. In such cases, an adversary that controls the WebRTC gateway can inspect the content of the media streams and trivially detect the transmission of covert payload. Gabriel Figueira, Diogo Barradas, Nuno Santos 0001 |
AsiaCCS | 2 |
| 2022 | Poster: User Sessions on Tor Onion Services: Can Colluding ISPs Deanonymize Them at Scale?abstractTor is the most popular anonymity network in the world. It relies on advanced security and obfuscation techniques to ensure the privacy of its users and free access to the Internet. However, the investigation of traffic correlation attacks against Tor Onion Services (OSes) has been relatively overlooked in the literature. In particular, determining whether it is possible to emulate a global passive adversary capable of deanonymizing the IP addresses of both the Tor OSes and of the clients accessing them has remained, so far, an open question. In this paper, we present ongoing work toward addressing this question and reveal some preliminary results on a scalable traffic correlation attack that can potentially be used to deanonymize Tor OS sessions. Our attack is based on a distributed architecture involving a group of colluding ISPs from across the world. After collecting Tor traffic samples at multiple vantage points, ISPs can run them through a pipeline where several stages of traffic classifiers employ complementary techniques that result in the deanonymization of OS sessions with high confidence (i.e., low false positives). We have responsibly disclosed our early results with the Tor Project team and are currently working not only on improving the effectiveness of our attack but also on developing countermeasures to preserve Tor users' privacy. Daniela Lopes, Pedro Medeiros, Jin-Dong Dong, Diogo Barradas, Bernardo Portela, João Vinagre, Bernardo Ferreira, Nicolas Christin, Nuno Santos 0001 |
CCS | 4 |
| 2021 | FlowLens: Enabling Efficient Flow Classification for ML-based Network Security Applications
Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues, Salvatore Signorello, Fernando M. V. Ramos, André Madeira |
NDSS | 1 |
| 2021 | Chinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of ChinaabstractThe Great Firewall of China (GFW) prevents Chinese citizens from accessing online content deemed objectionable by the Chinese government. One way it does this is to search for forbidden keywords in unencrypted packet streams. When it detects them, it terminates the offending stream by injecting TCP RST packets, and blocks further traffic between the same two hosts for a few minutes. Zachary Weinberg, Diogo Barradas, Nicolas Christin |
WWW | 2 |
| 2020 | Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTCabstractMany censorship circumvention tools rely on trusted proxies that allow users within censored regions to access blocked Internet content by tunneling it through a covert channel (e.g,. piggybacking on Skype video calls). However, building tools that can simultaneously (i) provide good bandwidth capacity for accommodating the typical activities of Internet users, and (ii) be secure against traffic analysis attacks has remained an open problem and a stumbling block to the practical adoption of such tools for censorship evasion. Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues, Vítor Nunes |
CCS | 1 |
| 2019 | Forensic analysis of communication records of messaging applications from physical memory
Diogo Barradas, Tiago Brito, David Duarte, Nuno Santos 0001, Luís E. T. Rodrigues |
Comput. Secur. | 1 |
| 2018 | Effective Detection of Multimedia Protocol Tunneling using Machine Learning
Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues |
USENIX Security Symposium | 1 |
| 2017 | Forensic Analysis of Communication Records of Web-based Messaging Applications from Physical Memory
Diogo Barradas, Tiago Brito, David Duarte, Nuno Santos 0001, Luís E. T. Rodrigues |
SECRYPT | 1 |
| 2017 | DeltaShaper: Enabling Unobservable Censorship-resistant TCP Tunneling over Videoconferencing StreamsabstractAbstract This paper studies the possibility of using the encrypted video channel of widely used videoconferencing applications, such as Skype, as a carrier for unobservable covert TCP/IP communications. We propose and evaluate different alternatives to encode information in the video stream in order to increase available throughput while preserving the packet-level characteristics of the video stream. We have built a censorship-resistant system, named DeltaShaper, which offers a data-link interface and supports TCP/IP applications that tolerate low throughput / high latency links. Our results show that it is possible to run standard protocols such as FTP, SMTP, or HTTP over Skype video streams. Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues |
Proc. Priv. Enhancing Technol. | 1 |