José Roldán Gómez

dblp:256/1478 · DBLP profile ↗
← Back
15ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0001-5787-1294ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 6 since 2021Systems, architecture and hardware · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Security and privacy · 1
YearPublicationVenuePosition
2026 Hybrid clustering-guided federated learning for robust intrusion detection in highly heterogeneous IoT environments
abstract
The growing complexity and scale of Internet of Things (IoT) ecosystems have intensified the emergence of cyber threats and amplified the impact of data heterogeneity across devices. These environments are characterised by their inherent hostility, comprising resource-limited and intermittently connected devices. Consequently, this poses a considerable challenge to the stability and reliability of conventional Federated Learning (FL) approaches. Standard aggregation schemes such as FedAvg, FedProx, FedAdam, and SCAFFOLD often fail under such extreme non-Independent and Identically Distributed (non-IID) conditions, leading to unstable convergence and biased global models. This work introduces a double-clustering federated architecture for intrusion detection that coordinates training at two levels. Locally, lightweight micro-clustering organises client-side updates into consistent groups, reducing the influence of inconsistent local updates. At the server level, density-based (HDBSCAN) clustering discovers evolving families of distributionally compatible clients, allowing coordination to adapt as heterogeneity evolves over time. Clustering is stabilised across rounds through a stability-aware assignment rule. Training then proceeds via family-wise aggregation, producing one expert model per family and a global fallback model for outliers and unassigned participants. Extensive experiments on three public IoT cybersecurity datasets, X-IIoTID, RT-IoT22, and Edge-IIoTset, demonstrate the robustness of the proposed strategy across both lightweight and Deep Learning (DL) models. The architecture achieves up to 19.9% higher F1-score than standard FL methods and maintains over 90% of its peak performance even under severe non-IID conditions, while keeping runtime variations within ± 15%. These results establish clustering-guided coordination as a practical and resilient foundation for federated intrusion detection, capable of sustaining high accuracy and stability in the most adversarial IoT environments.
Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001
Comput. Networks3
2026 Poisoning-Resilient Federated Learning for MEC-IoT Environments Using Blockchain
abstract
The rise of distributed architectures in Internet of Things (IoT) environments has significantly advanced both data processing and artificial intelligence. Notably, Multi-access Edge Computing (MEC) represents a distributed form of the Edge Computing paradigm, focussing on heterogeneous protocol management. In contrast, Federated Learning (FL) is an application-level framework designed to enable decentralised Machine Learning (ML) across devices without centralising data. Nevertheless, the combination of both technologies enables the creation of more efficient, scalable, and responsive systems. However, their integration into IoT brings substantial security challenges, including data poisoning, model manipulation, and the insertion of false nodes, all of which threaten the reliability of FL systems. Blockchain technology emerges as a promising solution to these challenges. It offers a decentralised, transparent, and immutable framework that ensures the authenticity and verification of data across the network. Through blockchain, node interactions are automated and secured, enhancing the integrity and trust in the learning process. This article proposes a blockchain-based architecture for FL within MEC-IoT systems, designed to mitigate security threats. The architecture emphasises data integrity, secure node interactions, and transparent audit trails while maintaining optimal model performance and accuracy, even under attack. It highlights the low resource consumption and minimal time overhead of blockchain integration, ensuring efficiency is not compromised. This integrated approach improves data security, supports secure collaborative learning, and fosters a more resilient and trustworthy IoT ecosystem.
Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001
ACM Trans. Internet Techn.3
2025 SecureAutoLoRa: An Automated Secure Registration Procedure for LoRaWAN Devices
abstract
Device registration in LoRaWAN systems can be a tedious process, particularly when managing a large number of devices. To automate this task, we previously developed the AutoLoraConfig protocol, although it includes vulnerabilities that attackers can exploit. To solve this, in this work we introduce the SecureAutoLoRa, a protocol designed to enhance security in the automated device registration process for LoRaWAN networks. SecureAutoLoRa blocks abuse of the guest DevEUI used in automated joins by obfuscating registration messages and enforcing a configurable positional security code that dictates where the real DevEUI appears across packets, markedly hindering unauthorized registrations.Results show that SecureAutoLoRa sharply reduces attackers’ success. Compared with AES-128 and SPECK, it complements standard encryption to provide a practical, layered defense suitable for large-scale LoRaWAN onboarding.
Lucas Mallen, Julio A. Sanguesa, José Roldán Gómez, Vicente Torres-Sanz, Francisco J. Martinez
MSWiM3
2025 Adaptive Federated Learning-Based Architecture for Intrusion Detection in IoT/IIoT Environments
abstract
The rapid expansion and growth of Internet of Things (IoT) and Industrial Internet of Things (IIoT) environments has led to an increase in the number of attacks and risks in these environments. This presents new cybersecurity challenges that require more advanced intrusion detection systems (IDS). However, IDS based on centralised Machine Learning (ML) face problems of scalability, latency, and privacy. In this context, Federated Learning (FL) offers a decentralised approach that allows multiple nodes to train models collaboratively without exposing sensitive data. This work presents a federated IDS tailored for IoT/IIoT environments and introduces FedWLA, an aggregation strategy that dynamically weights updates according to the quality and uncertainty of local data. The proposed architecture is evaluated through different IoT/IIoT traffic datasets orientated to cybersecurity and widely used in these environments. It shows comparable and even superior performance to centralised methods, with an average F1-Score ranging between 0.98 - 0.99 for the tests performed. Moreover, the proposed FedWLA strategy consistently outperforms other federated aggregation approaches, such as FedAvg and FedProx, particularly in heterogeneous scenarios. These results demonstrate the capability and potential of FL in intrusion detection, effectively leveraging the scalability and privacy advantages it offers.
Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001
SMC3
2025 A self-contained emulator for the forensic examination of IoE scenarios
Sergio Ruiz-Villafranca, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Roldán Gómez, José Luis Martínez 0001
Ad Hoc Networks4
2025 WFE-Tab: Overcoming limitations of TabPFN in IIoT-MEC environments with a weighted fusion ensemble-TabPFN model for improved IDS performance
abstract
In recent years we have seen the emergence of new industrial paradigms such as Industry 4.0/5.0 or the Industrial Internet of Things (IIoT). As the use of these new paradigms continues to grow, so do the number of threats and exploits that they face, which makes the IIoT a desirable target for cybercriminals . Furthermore, IIoT devices possess inherent limitations, primarily due to their limited resources. As a result, it is often impossible to detect attacks using solutions designed for other environments. Recently, Intrusion Detection Systems (IDS) based on Machine Learning (ML) have emerged as a solution that takes advantage of the large amount of data generated by IIoT devices to implement their functionality and achieve good performance , and the inclusion of the Multi-Access Edge Computing (MEC) paradigm in these environments provides the necessary computational resources to deploy IDS effectively. Furthermore, TabPFN has been considered as an attractive option for solving classification problems without the need to reprocess the data. However, TabPFN has certain drawbacks when it comes to the number of training samples and the maximum number of different classes that the model is capable of classifying. This makes TabPFN unsuitable for use when the dataset exceeds one of these limitations. In order to overcome such limitations, this paper presents a Weighted Fusion-Ensemble-based TabPFN (WFE-Tab) model to improve IDS performance in IIoT-MEC scenarios. The presented study employs a novel weighted fusion method to preprocess data into multiple subsets, generating different ensemble family TabPFN models. The resulting WFE-Tab model comprises four stages: data collection, data preprocessing , model training, and model evaluation. The performance of the WFE-Tab method is evaluated using key metrics such as Accuracy, Precision, Recall, and F1-Score, and validated using the Edge-IIoTset public dataset. The performance of the method is then compared with baseline and modern methods to evaluate its effectiveness, achieving an F1-Score performance of 99.81%.
Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001, Carlos Gañán
Future Gener. Comput. Syst.2
2024 A Concept Forensic Methodology For The Investigation Of IoT Cyberincidents
abstract
Abstract The number of Internet of Things (IoT) forensic investigations has increased considerably over recent years due to the weak nature of the security measures of its devices. In order to ensure the effectiveness and completeness of their examinations, investigators rely on forensic models, frameworks and methodologies. However, given the novelty of the environment, the existing ones are not refined enough, and the conventional counterparts do not satisfy the requirements of the IoT. Consequently, further improvements are needed in order for a more suitable IoT methodology to be designed. After reviewing the proposals from the research community for the development of procedures for performing IoT investigations, this article presents a practical concept methodology for conducting IoT forensic investigations that details step by step the whole examination process from its opening to its closing. In order to test its effectiveness and feasibility, it is submitted to a theoretical, a practical and a hybrid evaluation. Firstly, by comparing its level of detail, practicality and content with the related work. Secondly, by assessing its performance in two practical scenarios that depict real-life forensic investigations and the challenges that they present. And, finally, by studying how the existing models from the research community would have behaved in these cases. After performing these three different evaluations, it can be concluded that the results achieved by the proposed methodology were satisfactory, confirmed the feasibility of the proposal and showed clear benefits compared with the related work in terms of practicality and level of detail.
Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Roldán Gómez, José Luis Martínez 0001
Comput. J.3
2024 A TabPFN-based intrusion detection system for the industrial internet of things
abstract
Abstract The industrial internet of things (IIoT) has undergone rapid growth in recent years, which has resulted in an increase in the number of threats targeting both IIoT devices and their connecting technologies. However, deploying tools to counter these threats involves tackling inherent limitations, such as limited processing power, memory, and network bandwidth. As a result, traditional solutions, such as the ones used for desktop computers or servers, cannot be applied directly in the IIoT, and the development of new technologies is essential to overcome this issue. One approach that has shown potential for this new paradigm is the implementation of intrusion detection system (IDS) that rely on machine learning (ML) techniques. These IDSs can be deployed in the industrial control system or even at the edge layer of the IIoT topology. However, one of their drawbacks is that, depending on the factory’s specifications, it can be quite challenging to locate sufficient traffic data to train these models. In order to address this problem, this study introduces a novel IDS based on the TabPFN model, which can operate on small datasets of IIoT traffic and protocols, as not in general much traffic is generated in this environment. To assess its efficacy, it is compared against other ML algorithms, such as random forest, XGBoost, and LightGBM, by evaluating each method with different training set sizes and varying numbers of classes to classify. Overall, TabPFN produced the most promising outcomes, with a 10–20% differentiation in each metric. The best performance was observed when working with 1000 training set samples, obtaining an F1 score of 81% for 6-class classification and 72% for 10-class classification.
Sergio Ruiz-Villafranca, José Roldán Gómez, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001
J. Supercomput.2
2024 An automatic unsupervised complex event processing rules generation architecture for real-time IoT attacks detection
abstract
Abstract In recent years, the Internet of Things (IoT) has grown rapidly, as has the number of attacks against it. Certain limitations of the paradigm, such as reduced processing capacity and limited main and secondary memory, make it necessary to develop new methods for detecting attacks in real time as it is difficulty to adapt as has the techniques used in other paradigms. In this paper, we propose an architecture capable of generating complex event processing (CEP) rules for real-time attack detection in an automatic and completely unsupervised manner. To this end, CEP technology, which makes it possible to analyze and correlate a large amount of data in real time and can be deployed in IoT environments, is integrated with principal component analysis (PCA), Gaussian mixture models (GMM) and the Mahalanobis distance. This architecture has been tested in two different experiments that simulate real attack scenarios in an IoT network. The results show that the rules generated achieved an F1 score of .9890 in detecting six different IoT attacks in real time.
José Roldán Gómez, Jesús Martínez del Rincón, Juan Boubeta-Puig, José Luis Martínez 0001
Wirel. Networks1
2023 A MEC-IIoT intelligent threat detector based on machine learning boosted tree algorithms
abstract
In recent years, new management methods have appeared that mark the beginning of a new industrial revolution called Industry 4.0 or the Industrial Internet of Things (IIoT). IIoT brings together new emerging technologies, such as the Internet of Things (IoT), Deep Learning (DL) and Machine Learning (ML), that contribute to new applications, industrial processes and efficiency management in factories. This combination of new technologies and contexts is paired with Multi-access Edge Computing (MEC) to reduce costs through the virtualisation of networks and services. As these new paradigms increase in growth, so does the number of threats and vulnerabilities, making IIoT a very desirable target for cybercriminals. In addition, IIoT devices have certain intrinsic limitations, especially due to their limited resources, and this makes it impossible, in many cases, to detect attacks by using solutions designed for other paradigms. So it is necessary to design, implement and evaluate new solutions or adapt existing ones. Therefore, this paper proposes an intelligent threat detector based on boosted tree algorithms. Such detectors have been implemented and evaluated in an environment specifically designed to test IIoT deployments. In this way, we can learn how these algorithms, which have been successful in multiple contexts, behave in a paradigm with known constraints. The results obtained in the study show that our intelligent threat detector achieves a mean efficiency of between 95%–99% in the F1 Score metric, indicating that it is a good option for implementation in these scenarios.
Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, José Miguel Villalón Millán
Comput. Networks2
2023 An automatic complex event processing rules generation system for the recognition of real-time IoT attack patterns
abstract
The Internet of Things (IoT) has grown rapidly to become the core of many areas of application, leading to the integration of sensors, with IoT devices. However, the number of attacks against these types of devices has grown as fast as the paradigm itself. Certain inherent characteristics of the paradigm, as well as the limited computational capabilities of the devices involved, make it difficult to deploy security measures. This is why it is necessary to design, implement and study new solutions in the field of cybersecurity. In this paper, we propose an architecture that is capable of generating Complex Event Processing (CEP) rules automatically by integrating them with machine learning technologies. While the former is used to automatically detect attack patterns in real time, the latter, through the use of the Principal Component Analysis (PCA) algorithm, allows the characterization of events and the recognition of anomalies. This combination makes it possible to achieve efficient CEP rules at the computational level, with the results showing that the CEP rules obtained using our approach substantially improve upon the performance of the standard CEP rules, which are rules that are not generated by our proposal but can be defined independently by an expert in the field. Our proposal has achieved an F1-score of 0.98 on average, a 76 percent improvement in throughput over standard CEP rules, and a reduction in the network overhead of 86 percent over standard simple events, which are the simple events that are generated when our proposal is not used.
José Roldán Gómez, Juan Boubeta-Puig, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, Jesús Martínez del Rincón
Eng. Appl. Artif. Intell.1
2023 MECInOT: a multi-access edge computing and industrial internet of things emulator for the modelling and study of cybersecurity threats
abstract
Abstract In recent years, the Industrial Internet of Things (IIoT) has grown rapidly, a fact that has led to an increase in the number of cyberattacks that target this environment and the technologies that it brings together. Unfortunately, when it comes to using tools for stopping such attacks, it can be noticed that there are inherent weaknesses in this paradigm, such as limitations in computational capacity, memory and network bandwidth. Under these circumstances, the solutions used until now in conventional scenarios cannot be directly adopted by the IIoT, and so it is necessary to develop and design new ones that can effectively tackle this problem. Furthermore, these new solutions must be tested in order to verify their performance and viability, which requires testing architectures that are compatible with newly introduced IIoT topologies. With the aim of addressing these issues, this work proposes MECInOT, which is an architecture based on openLEON and capable of generating test scenarios for the IIoT environment. The performance of this architecture is validated by creating an intelligent threat detector based on tree-based algorithms, such as decision tree, random forest and other machine learning techniques. Which allows us to generate an intelligent and to demonstrate, we could generate an intelligent threat detector and demonstrate the suitability of our architecture for testing solutions in IIoT environments. In addition, by using MECInOT, we compare the performance of the different machine learning algorithms in an IIoT network. Firstly, we present the benefits of our proposal, and secondly, we describe the emulation of an IIoT environment while ensuring the repeatability of the experiments.
Sergio Ruiz-Villafranca, Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, José Roldán Gómez
J. Supercomput.4
2021 Attack Pattern Recognition in the Internet of Things using Complex Event Processing and Machine Learning
abstract
The Internet of Things (IoT) paradigm demands adapting traditional cybersecurity solutions to address the inherent limitations of IoT environments, in particular their low computational power and limited amount of memory and bandwidth. The Complex Event Processing (CEP) technology has proven to be useful in this context by deploying a CEP engine for detecting real-time attacks in an IoT network. However, CEP is only capable of detecting attacks that have been previously modeled as event patterns. This requires a domain expert who knows the conditions that must be satisfied so that certain attacks can be detected, thus identifying unmodeled ones is not possible. This paper aims to address this problem by proposing a machine learning algorithm that allows for the automatic creation of CEP patterns based on categorized data if the goal is to classify attacks, or even uncategorized data if the objective is to detect anomalies. An evaluation of the effectiveness of the automatically generated patterns for recognizing different attacks in IoT environments is also conducted in this paper.
José Roldán Gómez, Juan Boubeta-Puig, Juan Manuel Castelo Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001
SMC1
2020 Integrating complex event processing and machine learning: An intelligent architecture for detecting IoT security attacks
abstract
The Internet of Things (IoT) is growing globally at a fast pace: people now find themselves surrounded by a variety of IoT devices such as smartphones and wearables in their everyday lives. Additionally, smart environments, such as smart healthcare systems, smart industries and smart cities, benefit from sensors and actuators interconnected through the IoT. However, the increase in IoT devices has brought with it the challenge of promptly detecting and combating the cybersecurity attacks and threats that target them, including malware, privacy breaches and denial of service attacks, among others. To tackle this challenge, this paper proposes an intelligent architecture that integrates Complex Event Processing (CEP) technology and the Machine Learning (ML) paradigm in order to detect different types of IoT security attacks in real time. In particular, such an architecture is capable of easily managing event patterns whose conditions depend on values obtained by ML algorithms. Additionally, a model-driven graphical tool for security attack pattern definition and automatic code generation is provided, hiding all the complexity derived from implementation details from domain experts. The proposed architecture has been applied in the case of a healthcare IoT network to validate its ability to detect attacks made by malicious devices. The results obtained demonstrate that this architecture satisfactorily fulfils its objectives.
José Roldán Gómez, Juan Boubeta-Puig, José Luis Martínez 0001, Guadalupe Ortiz 0001
Expert Syst. Appl.1
2020 Automatic Analysis Architecture of IoT Malware Samples
abstract
The weakness of the security measures implemented on IoT devices, added to the sensitivity of the data that they handle, has created an attractive environment for cybercriminals to carry out attacks. To do so, they develop malware to compromise devices and control them. The study of malware samples is a crucial task in order to gain information on how to protect these devices, but it is impossible to manually do this due to the immense number of existing samples. Moreover, in the IoT, coexist multiple hardware architectures, such as ARM, PowerPC, MIPS, Intel 8086, or x64-86, which enlarges even more the quantity of malicious software. In this article, a modular solution to automatically analyze IoT malware samples from these architectures is proposed. In addition, the proposal is subjected to evaluation, analyzing a testbed of 1500 malware samples, proving that it is an effective approach to rapidly examining malicious software compiled for any architecture.
Javier Carrillo Mondéjar, Juan Manuel Castelo Gómez, Carlos Núñez-Gómez, José Roldán Gómez, José Luis Martínez 0001
Secur. Commun. Networks4