VLDB 2026 Research / reviewers in the wild / expert
Javier Carrillo Mondéjar
dblp:256/1392
· DBLP profile ↗
17ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0001-8371-4305ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 2 first-author · 4 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hybrid clustering-guided federated learning for robust intrusion detection in highly heterogeneous IoT environmentsabstractThe growing complexity and scale of Internet of Things (IoT) ecosystems have intensified the emergence of cyber threats and amplified the impact of data heterogeneity across devices. These environments are characterised by their inherent hostility, comprising resource-limited and intermittently connected devices. Consequently, this poses a considerable challenge to the stability and reliability of conventional Federated Learning (FL) approaches. Standard aggregation schemes such as FedAvg, FedProx, FedAdam, and SCAFFOLD often fail under such extreme non-Independent and Identically Distributed (non-IID) conditions, leading to unstable convergence and biased global models. This work introduces a double-clustering federated architecture for intrusion detection that coordinates training at two levels. Locally, lightweight micro-clustering organises client-side updates into consistent groups, reducing the influence of inconsistent local updates. At the server level, density-based (HDBSCAN) clustering discovers evolving families of distributionally compatible clients, allowing coordination to adapt as heterogeneity evolves over time. Clustering is stabilised across rounds through a stability-aware assignment rule. Training then proceeds via family-wise aggregation, producing one expert model per family and a global fallback model for outliers and unassigned participants. Extensive experiments on three public IoT cybersecurity datasets, X-IIoTID, RT-IoT22, and Edge-IIoTset, demonstrate the robustness of the proposed strategy across both lightweight and Deep Learning (DL) models. The architecture achieves up to 19.9% higher F1-score than standard FL methods and maintains over 90% of its peak performance even under severe non-IID conditions, while keeping runtime variations within ± 15%. These results establish clustering-guided coordination as a practical and resilient foundation for federated intrusion detection, capable of sustaining high accuracy and stability in the most adversarial IoT environments. Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001 |
Comput. Networks | 4 |
| 2026 | Characterizing tactics, techniques, and procedures in the macOS threat landscapeabstractAs macOS systems increasingly become malware targets, understanding the tactics, techniques, and procedures (TTPs) used by adversaries is essential to improving defense strategies. This paper provides a systematic and detailed analysis of macOS malware using the MITRE ATT&CK framework, focusing on TTPs at key stages of the malware attack cycle. Leveraging a comprehensive dataset of 57,636 macOS malware samples collected between November 2006 and October 2024, we employ both static and dynamic analysis techniques to uncover patterns in adversary behavior. Our analysis, primarily based on static analysis techniques, offers a broad representation of macOS malware and highlights common characteristics across samples. While we only partially explore dynamic behaviors, we identify recurring patterns that align with specific TTPs in the MITRE ATT&CK framework, such as persistence and defense evasion. This mapping contributes to a more structured understanding of macOS threats and can help inform future detection and mitigation efforts. Daniel Lastanao Miró, Javier Carrillo Mondéjar, Ricarddo J. Rodríguez |
Comput. Secur. | 2 |
| 2026 | Poisoning-Resilient Federated Learning for MEC-IoT Environments Using BlockchainabstractThe rise of distributed architectures in Internet of Things (IoT) environments has significantly advanced both data processing and artificial intelligence. Notably, Multi-access Edge Computing (MEC) represents a distributed form of the Edge Computing paradigm, focussing on heterogeneous protocol management. In contrast, Federated Learning (FL) is an application-level framework designed to enable decentralised Machine Learning (ML) across devices without centralising data. Nevertheless, the combination of both technologies enables the creation of more efficient, scalable, and responsive systems. However, their integration into IoT brings substantial security challenges, including data poisoning, model manipulation, and the insertion of false nodes, all of which threaten the reliability of FL systems. Blockchain technology emerges as a promising solution to these challenges. It offers a decentralised, transparent, and immutable framework that ensures the authenticity and verification of data across the network. Through blockchain, node interactions are automated and secured, enhancing the integrity and trust in the learning process. This article proposes a blockchain-based architecture for FL within MEC-IoT systems, designed to mitigate security threats. The architecture emphasises data integrity, secure node interactions, and transparent audit trails while maintaining optimal model performance and accuracy, even under attack. It highlights the low resource consumption and minimal time overhead of blockchain integration, ensuring efficiency is not compromised. This integrated approach improves data security, supports secure collaborative learning, and fosters a more resilient and trustworthy IoT ecosystem. Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001 |
ACM Trans. Internet Techn. | 4 |
| 2025 | Adaptive Federated Learning-Based Architecture for Intrusion Detection in IoT/IIoT EnvironmentsabstractThe rapid expansion and growth of Internet of Things (IoT) and Industrial Internet of Things (IIoT) environments has led to an increase in the number of attacks and risks in these environments. This presents new cybersecurity challenges that require more advanced intrusion detection systems (IDS). However, IDS based on centralised Machine Learning (ML) face problems of scalability, latency, and privacy. In this context, Federated Learning (FL) offers a decentralised approach that allows multiple nodes to train models collaboratively without exposing sensitive data. This work presents a federated IDS tailored for IoT/IIoT environments and introduces FedWLA, an aggregation strategy that dynamically weights updates according to the quality and uncertainty of local data. The proposed architecture is evaluated through different IoT/IIoT traffic datasets orientated to cybersecurity and widely used in these environments. It shows comparable and even superior performance to centralised methods, with an average F1-Score ranging between 0.98 - 0.99 for the tests performed. Moreover, the proposed FedWLA strategy consistently outperforms other federated aggregation approaches, such as FedAvg and FedProx, particularly in heterogeneous scenarios. These results demonstrate the capability and potential of FL in intrusion detection, effectively leveraging the scalability and privacy advantages it offers. Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001 |
SMC | 4 |
| 2025 | A self-contained emulator for the forensic examination of IoE scenarios
Sergio Ruiz-Villafranca, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Roldán Gómez, José Luis Martínez 0001 |
Ad Hoc Networks | 3 |
| 2025 | Identifying runtime libraries in statically linked linux binariesabstractVulnerabilities in unpatched applications can originate from third-party dependencies in statically linked applications, as they must be relinked each time to take advantage of libraries that have been updated to fix any vulnerability. Despite this, malware binaries are often statically linked to ensure they run on target platforms and to complicate malware analysis . In this sense, identification of libraries in malware analysis becomes crucial to help filter out those library functions and focus on malware function analysis. In this paper, we introduce MANTILLA , a system for identifying runtime libraries in statically linked Linux-based binaries. Our system is based on radare2 to identify functions and extract their features (independent of the underlying architecture of the binary) through static binary analysis and on the K-nearest neighbors supervised machine learning model and a majority rule to predict final values. MANTILLA is evaluated on a dataset consisting of binaries built for different architectures ( MIPSeb , ARMel , Intel x86 , and Intel x86-64 ) and different runtime libraries ( uClibc , glibc , and musl ), achieving very high accuracy. We also evaluate it in two case studies . First, using a dataset of binary files belonging to the binutils collection and second, using an IoT malware dataset. In both cases, good accuracy results are obtained both in terms of runtime library detection (94.4% and 95.5%, respectively) and architecture identification (100% and 98.6%, respectively). Javier Carrillo Mondéjar, Ricardo J. Rodríguez |
Future Gener. Comput. Syst. | 1 |
| 2025 | WFE-Tab: Overcoming limitations of TabPFN in IIoT-MEC environments with a weighted fusion ensemble-TabPFN model for improved IDS performanceabstractIn recent years we have seen the emergence of new industrial paradigms such as Industry 4.0/5.0 or the Industrial Internet of Things (IIoT). As the use of these new paradigms continues to grow, so do the number of threats and exploits that they face, which makes the IIoT a desirable target for cybercriminals . Furthermore, IIoT devices possess inherent limitations, primarily due to their limited resources. As a result, it is often impossible to detect attacks using solutions designed for other environments. Recently, Intrusion Detection Systems (IDS) based on Machine Learning (ML) have emerged as a solution that takes advantage of the large amount of data generated by IIoT devices to implement their functionality and achieve good performance , and the inclusion of the Multi-Access Edge Computing (MEC) paradigm in these environments provides the necessary computational resources to deploy IDS effectively. Furthermore, TabPFN has been considered as an attractive option for solving classification problems without the need to reprocess the data. However, TabPFN has certain drawbacks when it comes to the number of training samples and the maximum number of different classes that the model is capable of classifying. This makes TabPFN unsuitable for use when the dataset exceeds one of these limitations. In order to overcome such limitations, this paper presents a Weighted Fusion-Ensemble-based TabPFN (WFE-Tab) model to improve IDS performance in IIoT-MEC scenarios. The presented study employs a novel weighted fusion method to preprocess data into multiple subsets, generating different ensemble family TabPFN models. The resulting WFE-Tab model comprises four stages: data collection, data preprocessing , model training, and model evaluation. The performance of the WFE-Tab method is evaluated using key metrics such as Accuracy, Precision, Recall, and F1-Score, and validated using the Edge-IIoTset public dataset. The performance of the method is then compared with baseline and modern methods to evaluate its effectiveness, achieving an F1-Score performance of 99.81%. Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001, Carlos Gañán |
Future Gener. Comput. Syst. | 3 |
| 2024 | A Concept Forensic Methodology For The Investigation Of IoT CyberincidentsabstractAbstract The number of Internet of Things (IoT) forensic investigations has increased considerably over recent years due to the weak nature of the security measures of its devices. In order to ensure the effectiveness and completeness of their examinations, investigators rely on forensic models, frameworks and methodologies. However, given the novelty of the environment, the existing ones are not refined enough, and the conventional counterparts do not satisfy the requirements of the IoT. Consequently, further improvements are needed in order for a more suitable IoT methodology to be designed. After reviewing the proposals from the research community for the development of procedures for performing IoT investigations, this article presents a practical concept methodology for conducting IoT forensic investigations that details step by step the whole examination process from its opening to its closing. In order to test its effectiveness and feasibility, it is submitted to a theoretical, a practical and a hybrid evaluation. Firstly, by comparing its level of detail, practicality and content with the related work. Secondly, by assessing its performance in two practical scenarios that depict real-life forensic investigations and the challenges that they present. And, finally, by studying how the existing models from the research community would have behaved in these cases. After performing these three different evaluations, it can be concluded that the results achieved by the proposed methodology were satisfactory, confirmed the feasibility of the proposal and showed clear benefits compared with the related work in terms of practicality and level of detail. Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Roldán Gómez, José Luis Martínez 0001 |
Comput. J. | 2 |
| 2024 | A TabPFN-based intrusion detection system for the industrial internet of thingsabstractAbstract The industrial internet of things (IIoT) has undergone rapid growth in recent years, which has resulted in an increase in the number of threats targeting both IIoT devices and their connecting technologies. However, deploying tools to counter these threats involves tackling inherent limitations, such as limited processing power, memory, and network bandwidth. As a result, traditional solutions, such as the ones used for desktop computers or servers, cannot be applied directly in the IIoT, and the development of new technologies is essential to overcome this issue. One approach that has shown potential for this new paradigm is the implementation of intrusion detection system (IDS) that rely on machine learning (ML) techniques. These IDSs can be deployed in the industrial control system or even at the edge layer of the IIoT topology. However, one of their drawbacks is that, depending on the factory’s specifications, it can be quite challenging to locate sufficient traffic data to train these models. In order to address this problem, this study introduces a novel IDS based on the TabPFN model, which can operate on small datasets of IIoT traffic and protocols, as not in general much traffic is generated in this environment. To assess its efficacy, it is compared against other ML algorithms, such as random forest, XGBoost, and LightGBM, by evaluating each method with different training set sizes and varying numbers of classes to classify. Overall, TabPFN produced the most promising outcomes, with a 10–20% differentiation in each metric. The best performance was observed when working with 1000 training set samples, obtaining an F1 score of 81% for 6-class classification and 72% for 10-class classification. Sergio Ruiz-Villafranca, José Roldán Gómez, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001 |
J. Supercomput. | 4 |
| 2023 | A MEC-IIoT intelligent threat detector based on machine learning boosted tree algorithmsabstractIn recent years, new management methods have appeared that mark the beginning of a new industrial revolution called Industry 4.0 or the Industrial Internet of Things (IIoT). IIoT brings together new emerging technologies, such as the Internet of Things (IoT), Deep Learning (DL) and Machine Learning (ML), that contribute to new applications, industrial processes and efficiency management in factories. This combination of new technologies and contexts is paired with Multi-access Edge Computing (MEC) to reduce costs through the virtualisation of networks and services. As these new paradigms increase in growth, so does the number of threats and vulnerabilities, making IIoT a very desirable target for cybercriminals. In addition, IIoT devices have certain intrinsic limitations, especially due to their limited resources, and this makes it impossible, in many cases, to detect attacks by using solutions designed for other paradigms. So it is necessary to design, implement and evaluate new solutions or adapt existing ones. Therefore, this paper proposes an intelligent threat detector based on boosted tree algorithms. Such detectors have been implemented and evaluated in an environment specifically designed to test IIoT deployments. In this way, we can learn how these algorithms, which have been successful in multiple contexts, behave in a paradigm with known constraints. The results obtained in the study show that our intelligent threat detector achieves a mean efficiency of between 95%–99% in the F1 Score metric, indicating that it is a good option for implementation in these scenarios. Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, José Miguel Villalón Millán |
Comput. Networks | 3 |
| 2023 | An automatic complex event processing rules generation system for the recognition of real-time IoT attack patternsabstractThe Internet of Things (IoT) has grown rapidly to become the core of many areas of application, leading to the integration of sensors, with IoT devices. However, the number of attacks against these types of devices has grown as fast as the paradigm itself. Certain inherent characteristics of the paradigm, as well as the limited computational capabilities of the devices involved, make it difficult to deploy security measures. This is why it is necessary to design, implement and study new solutions in the field of cybersecurity. In this paper, we propose an architecture that is capable of generating Complex Event Processing (CEP) rules automatically by integrating them with machine learning technologies. While the former is used to automatically detect attack patterns in real time, the latter, through the use of the Principal Component Analysis (PCA) algorithm, allows the characterization of events and the recognition of anomalies. This combination makes it possible to achieve efficient CEP rules at the computational level, with the results showing that the CEP rules obtained using our approach substantially improve upon the performance of the standard CEP rules, which are rules that are not generated by our proposal but can be defined independently by an expert in the field. Our proposal has achieved an F1-score of 0.98 on average, a 76 percent improvement in throughput over standard CEP rules, and a reduction in the network overhead of 86 percent over standard simple events, which are the simple events that are generated when our proposal is not used. José Roldán Gómez, Juan Boubeta-Puig, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, Jesús Martínez del Rincón |
Eng. Appl. Artif. Intell. | 3 |
| 2023 | HALE-IoT: Hardening Legacy Internet of Things Devices by Retrofitting Defensive Firmware Modifications and ImplantsabstractInternet of Things (IoT) devices and their firmware are notorious for their lifelong vulnerabilities. As device infection increases, vendors also fail to release patches at a competitive pace. Despite security in acrshort IoT being an active area of research, prior work has mainly focused on vulnerability detection and exploitation, threat modeling, and protocol security. However, these methods are ineffective in preventing attacks against legacy and End-Of-Life devices that are already vulnerable. Current research mainly focuses on implementing and demonstrating the potential of malicious modifications. Hardening emerges as an effective solution to provide acrshort IoT devices with an additional layer of defense. In this article, we bridge these gaps through the design of $\textit {HALE-IoT}$ , a generically applicable systematic approach to HArdening LEgacy acrshort IoT non-low-end devices by retrofitting defensive firmware modifications without access to the original source code. $\textit {HALE-IoT}$ approaches this nontrivial task via binary firmware reversing and modification while being underpinned by a semiautomated toolset that aims to keep cybersecurity of such devices in a hale state. Our focus is on both modern and, especially, legacy or obsolete acrshort IoT devices as they become increasingly prevalent. To evaluate the effectiveness and efficiency of HALE-IoT, we apply it to a wide range of acrshort IoT devices by retrofitting 395 firmware images with defensive implants containing an intrusion prevention system in the form of a Web Application Firewall (for prevention of Web-attack vectors), and an HTTPS-proxy (for latest and full end-to-end HTTPS support) using emulation. We also test our approach on four physical devices, where we show that HALE-IoT successfully runs on protected and quite constrained devices with as low as 32 MB of RAM and 8 MB of storage. Overall, in our evaluation, we achieve good performance and reliability with a remarkably accurate detection and prevention rate for attacks coming from both real CVEs and synthetic exploits. Javier Carrillo Mondéjar, Hannu Turtiainen, Andrei Costin, José Luis Martínez 0001, Guillermo Suarez-Tangil |
IEEE Internet Things J. | 1 |
| 2023 | MECInOT: a multi-access edge computing and industrial internet of things emulator for the modelling and study of cybersecurity threatsabstractAbstract In recent years, the Industrial Internet of Things (IIoT) has grown rapidly, a fact that has led to an increase in the number of cyberattacks that target this environment and the technologies that it brings together. Unfortunately, when it comes to using tools for stopping such attacks, it can be noticed that there are inherent weaknesses in this paradigm, such as limitations in computational capacity, memory and network bandwidth. Under these circumstances, the solutions used until now in conventional scenarios cannot be directly adopted by the IIoT, and so it is necessary to develop and design new ones that can effectively tackle this problem. Furthermore, these new solutions must be tested in order to verify their performance and viability, which requires testing architectures that are compatible with newly introduced IIoT topologies. With the aim of addressing these issues, this work proposes MECInOT, which is an architecture based on openLEON and capable of generating test scenarios for the IIoT environment. The performance of this architecture is validated by creating an intelligent threat detector based on tree-based algorithms, such as decision tree, random forest and other machine learning techniques. Which allows us to generate an intelligent and to demonstrate, we could generate an intelligent threat detector and demonstrate the suitability of our architecture for testing solutions in IIoT environments. In addition, by using MECInOT, we compare the performance of the different machine learning algorithms in an IIoT network. Firstly, we present the benefits of our proposal, and secondly, we describe the emulation of an IIoT environment while ensuring the repeatability of the experiments. Sergio Ruiz-Villafranca, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, José Roldán Gómez |
J. Supercomput. | 2 |
| 2022 | On how VoIP attacks foster the malicious call ecosystemabstractSwitched telephone networks are a key and ubiquitous infrastructure. Recent technological advances have integrated modern and inexpensive systems into these networks in order to use the Internet to place calls via Voice over IP (VoIP). The evolution of this technology has also led to an increase in the number and sophistication of the techniques used by criminals to commit fraud. Specifically, with the emergence of VoIP, attackers can now adapt tools commonly used by cybercriminals, such as botnets, to make their attacks more complex and insidious. For example, through bots they can dial multiple numbers automatically, enabling them to target a greater number of victims, and do so more quickly. While recent studies have shed light on how certain parts of this ecosystem work, it is still unclear how attacks on VoIP systems contribute to this type of fraud. This paper presents a novel VoIP honeypot that captures voice interactions, in addition to employing low-level telemetry. With the study of how attackers obtain access to our honeypot and the actions they perform, we present an overview of the most prevalent types of fraud used in this ecosystem, including unique insights into the origin of the attacks and the destination of calls made through our architecture. Finally, we analyze in depth the actions taken to study the different types of telephony fraud. Javier Carrillo Mondéjar, José Luis Martínez 0001, Guillermo Suarez-Tangil |
Comput. Secur. | 1 |
| 2021 | Attack Pattern Recognition in the Internet of Things using Complex Event Processing and Machine LearningabstractThe Internet of Things (IoT) paradigm demands adapting traditional cybersecurity solutions to address the inherent limitations of IoT environments, in particular their low computational power and limited amount of memory and bandwidth. The Complex Event Processing (CEP) technology has proven to be useful in this context by deploying a CEP engine for detecting real-time attacks in an IoT network. However, CEP is only capable of detecting attacks that have been previously modeled as event patterns. This requires a domain expert who knows the conditions that must be satisfied so that certain attacks can be detected, thus identifying unmodeled ones is not possible. This paper aims to address this problem by proposing a machine learning algorithm that allows for the automatic creation of CEP patterns based on categorized data if the goal is to classify attacks, or even uncategorized data if the objective is to detect anomalies. An evaluation of the effectiveness of the automatically generated patterns for recognizing different attacks in IoT environments is also conducted in this paper. José Roldán Gómez, Juan Boubeta-Puig, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001 |
SMC | 4 |
| 2020 | Characterizing Linux-based malware: Findings and recent trendsabstractMalware targeting interconnected infrastructures has surged in recent years. A major factor driving this phenomenon is the proliferation of large networks of poorly secured IoT devices. This is exacerbated by the commoditization of the malware development industry, in which tools can be readily obtained in specialized hacking forums or underground markets. However, despite the great interest in targeting this infrastructure, there is little understanding of what the main features of this type of malware are, or the motives of the criminals behind it, apart from the classic denial of service attacks. This is vital to modern malware forensics, where analyses are required to measure the trustworthiness of files collected at large during an investigation, but also to confront challenges posed by tech-savvy criminals (e.g., Trojan Horse Defense). In this paper, we present a comprehensive characterization of Linux-based malware. Our study is tailored to IoT malware and it leverages automated techniques using both static and dynamic analysis to classify malware into related threats. By looking at the most representative dataset of Linux-based malware collected by the community to date, we are able to show that our system can accurately characterize known threats. As a key novelty, we use our system to investigate a number of threats unknown to the community. We do this in two steps. First, we identify known patterns within an unlabeled dataset using a classifier trained with the labeled dataset. Second, we combine our features with a custom distance function to discover new threats by clustering together similar samples. We further study each of the unknown clusters by using state-of-the-art reverse engineering and forensic techniques and our expertise as malware analysts. We provide an in-depth analysis of what the most recent unknown trends are through a number of case studies. Among other findings, we observe that: i) crypto-mining malware is permeating the IoT infrastructure, ii) the level of sophistication is increasing, and iii) there is a rapid proliferation of new variants with minimal investment in infrastructure. Javier Carrillo Mondéjar, José Luis Martínez 0001, Guillermo Suarez-Tangil |
Future Gener. Comput. Syst. | 1 |
| 2020 | Automatic Analysis Architecture of IoT Malware SamplesabstractThe weakness of the security measures implemented on IoT devices, added to the sensitivity of the data that they handle, has created an attractive environment for cybercriminals to carry out attacks. To do so, they develop malware to compromise devices and control them. The study of malware samples is a crucial task in order to gain information on how to protect these devices, but it is impossible to manually do this due to the immense number of existing samples. Moreover, in the IoT, coexist multiple hardware architectures, such as ARM, PowerPC, MIPS, Intel 8086, or x64-86, which enlarges even more the quantity of malicious software. In this article, a modular solution to automatically analyze IoT malware samples from these architectures is proposed. In addition, the proposal is subjected to evaluation, analyzing a testbed of 1500 malware samples, proving that it is an effective approach to rapidly examining malicious software compiled for any architecture. Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, Carlos Núñez-Gómez, José Roldán Gómez, José Luis Martínez 0001 |
Secur. Commun. Networks | 1 |