VLDB 2026 Research / reviewers in the wild / expert
Pedro R. M. Inácio
dblp:26/2761 · also Pedro Ricardo M. Inácio
· DBLP profile ↗
27ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0001-8221-0666ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 3 since 2021Security and privacy · 7 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ZQBA: Zero Query Black-Box Adversarial Attack
Joana Cabral Costa, Tiago Roxo, Hugo Proença 0001, Pedro R. M. Inácio |
ICAART (5) | 4 |
| 2026 | X-IoMT: A Cross-Layer IoMT Dataset for Anomaly Detection With FGSM- and PGD-Based Adversarial AugmentationabstractWith the growing adoption of the Internet of Medical Things (IoMT), concerns around security, reliability, and anomaly detection across heterogeneous system layers are increasing. The essence of contemporary anomaly detection lies in Machine Learning (ML), training models on datasets for the desired functionality. Nonetheless, currently available datasets are mostly insufficiently supported with multi-layer analysis, as they usually target a single architectural layer or a narrow attack type. To close this gap, we offer X-IoMT, a publicly available dataset designed to enable the research of anomaly detection in IoMT environments. In the Internet of Things (IoT) architecture, the X-IoMT data embodies anomalies from the perception, network, and application layers. Besides, it incorporates adversarial perturbations by Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) under both L2 and L∞ norms with extra adversarial augmentation: both on detection performance under common attacks and on resilience against adversarially manipulated samples. Thus, X-IoMT could be an important tool for evaluating and benchmarking reliable anomaly detection models in IoMT scenarios with cross-layer attack coverage and extra adversarial augmentation. This paper contributes with the presentation of the dataset, inherently aiming to support the advancement of more reliable and secure IoMT systems. Rui P. Pinto, Bruno M. C. Silva, Pedro R. M. Inácio |
IEEE Internet Things J. | 3 |
| 2025 | ASDnB: Merging Face with Body Cues For Robust Active Speaker DetectionabstractState-of-the-art Active Speaker Detection (ASD) approaches mainly use audio and facial features as input. However, the main hypothesis in this paper is that body dynamics is also highly correlated to "speaking" (and "listening") actions and should be particularly useful in wild conditions (e.g., surveillance settings), where face cannot be reliably accessed. We propose ASDnB, a model that singularly integrates face with body information by merging the inputs at different steps of feature extraction. Our approach splits 3D convolution into 2D and 1D to reduce computation cost without loss of performance, and is trained with adaptive weight feature importance for improved complement of face with body data. Our experiments show that ASDnB achieves state-of-the-art results in the benchmark dataset (AVA-ActiveSpeaker), in the challenging data of WASD, and in cross-domain settings using Columbia. This way, ASDnB can perform in multiple settings, which is positively regarded as a strong baseline for robust ASD models (code available at https://github.com/Tiago-Roxo/ASDnB). Tiago Roxo, Joana Cabral Costa, Pedro R. M. Inácio, Hugo Proença 0001 |
IJCB | 3 |
| 2025 | Anomaly Detection in the Internet of Medical Things: Design and Evaluation of a Cross Layer DatasetabstractThe Internet of Medical Things (IoMT) is a technological paradigm that enables continuous health monitoring, yet it also introduces significant security and reliability challenges, as systems are not only exposed to cyberattacks but also to devicelevel anomalies. Modern anomaly detection increasingly relies on machine learning (ML). However, the availability of datasets to train or test ML models remains limited and lacking diversity in anomaly types. This work presents the X-IoMT dataset, a multi-layer anomaly dataset comprising perception, network, and application-layer anomalies, collected from real IoMT devices. Device failures, cyberattacks, and clinical irregularities are examples of anomalies that allow for an extensive evaluation of anomaly detection techniques. ML models were used to analyze the dataset in binary, layer-wise, and multiclass classification tasks. Accuracy, precision, recall, and F1-score were used to assess performance. The findings show the challenge and the realism of the X-IoMT dataset, with more advanced methods capturing its varied anomaly patterns while simpler models found it difficult to handle. Rui P. Pinto, Bruno M. C. Silva, Pedro R. M. Inácio |
NCA | 3 |
| 2024 | Analysis of the Capability and Training of Chat Bots in the Generation of Rules for Firewall or Intrusion Detection SystemsabstractLarge Language Models (LLMs) have the potential to aid in closing the knowledge gap in several specific technical areas, such as cybersecurity, by providing a means to translate instructions defined in natural language into specialized system or software specifications (e.g., firewall rules). The work described herein aims at an evaluation of the capability of LLMs to generate rules for firewall and Intrusion Detection Systems (IDSs). A preliminary assessment has shown that widely available chat bots have limited capability to generate correct rules and that caution is needed when using their outputs for the aforementioned objective. This work explores three fine-tuning approaches to address these limitations, each of them with a different objective and achieving distinct success rates. The first approach aimed at testing how well the model was able to use the knowledge obtained from the prompts when the question was structured differently, achieving a success rate of 89%. The second approach aimed at testing how well the model could link the knowledge obtained from two different prompts and reached a success rate of 61%. The final approach aimed at testing if the model could create complex rules by first learning simple rules, achieving a success rate of 79%. It can be concluded that fine-tuning is sufficient to improve chat bots into creating syntactically and technically correct rules for firewalls and IDSs. Results suggest that the development of a specialized model for as many attacks, firewalls and IDSs can indeed be achieved. Bernardo Louro, Raquel Abreu, Joana Cabral Costa, João B. F. Sequeiros, Pedro R. M. Inácio |
ARES | 5 |
| 2024 | An Approach to Attack Modeling for the IoT: Creating Attack Trees from System Descriptions
João B. F. Sequeiros, Francisco T. Chimuco, Tiago M. C. Simões, Mário M. Freire, Pedro R. M. Inácio |
AINA (2) | 5 |
| 2022 | Impact of Self C Parameter on SVM-based Classification of Encrypted Multimedia Peer-to-Peer Traffic
Vanice Canuto Cunha, Damien Magoni, Pedro R. M. Inácio, Mário M. Freire |
AINA (1) | 3 |
| 2021 | Performance Evaluation of Container-Level Anomaly-Based Intrusion Detection Systems for Multi-Tenant Applications Using Machine Learning AlgorithmsabstractThe virtualization of computing resources provided by containers has gained increasing attention and has been widely used in cloud computing. This new demand for container technology has been growing and the use of Docker and Kubernetes is considerable. According to recent technology surveys, containers are now mainstream. However, currently, one of the major challenges rises from the fact that multiple containers, with different owners, may cohabit on the same host. In container-based multi-tenant environments, security issues are of major concern. In this paper we investigate the performance of container-level anomaly-based intrusion detection systems for multi-tenant applications. We investigate the use of Bag of System Calls (BoSC) technique and the sliding window with the classifier and we consider eight machine learning algorithms for classification purposes. We show that among the eight machine learning algorithms, the best classification results are obtained with Decision Tree and Random Forest which lead to an F-Measure of 99.8%, using a sliding window with a size of 30 and the BoSC algorithm in both cases. We also show that, although both Decision Tree and Random Forest algorithms leads to the best classification results, the Decision Tree algorithm has a shorter execution time and consumes less CPU and memory than the Random Forest. Marcos Cavalcanti, Pedro R. M. Inácio, Mário M. Freire |
ARES | 2 |
| 2021 | Detection of reduction-of-quality DDoS attacks using Fuzzy Logic and machine learning algorithms
Vinícius de Miranda Rios, Pedro R. M. Inácio, Damien Magoni, Mário M. Freire |
Comput. Networks | 2 |
| 2021 | Performance evaluation of the SRE and SBPG components of the IoT hardware platform security advisor frameworkabstractThe applications of Internet of Things (IoT) and associated technologies have been spreading rapidly across a wide range of domains, including environmental monitoring, home automation, and supply chain, having a significant bearing on the social and economic well-being of humans as well as enhancing environmental sustainability. In recent years, however, there have been several data breaches and other security and privacy incidents involving IoT devices , which have attracted significant attention from the research community in both academia and industry. This has resulted in a surge of proposals put forward by many researchers, including IoT blockchain-based security solutions, IoT intrusion detection systems , IoT authentication systems , and IoT security analytics . While these proposals are aimed at addressing various IoT security and privacy-related issues, many of these solutions arguably seem not to focus on helping designers and developers with little or no security expertise in start-up companies to produce secure IoT systems. To this end, the IoT Hardware Platform Security Advisor (IoT-HarPSecA) framework was proposed to foster the design and implementation of secure IoT systems. In this paper, we present the performance and usability evaluation of the Security Requirements Elicitation (SRE) and Security Best Practice Guidelines (SBPG) component tools of IoT-HarPSecA, which are two of the three component tools of the security framework. Results show that the two components of the IoT-HarPSecA framework can facilitate the development of secure IoT systems and that the SRE and SBPG tools are easy to use. Musa G. Samaila, Carolina Galvão Lopes, Édi Aires, João B. F. Sequeiros, Tiago M. C. Simões, Mário M. Freire, Pedro R. M. Inácio |
Comput. Networks | 7 |
| 2020 | Classification of Encrypted Internet Traffic Using Kullback-Leibler Divergence and Euclidean Distance
Vanice Canuto Cunha, Arturo A. Z. Zavala, Pedro R. M. Inácio, Damien Magoni, Mário M. Freire |
AINA | 3 |
| 2019 | IoT-HarPSecA: A Framework for Facilitating the Design and Development of Secure IoT DevicesabstractThe exponential growth in the number of Internet of Things (IoT) devices and applications in recent years can be attributed partly to the emergence of several new IoT startup companies and potential applications. While many of these startups offer significant innovations in the IoT, some of them lack security expertise, resulting in the development of ill-equipped IoT devices and applications in terms of security. For example, one of the fundamental problems faced by non-security experts in the IoT space is how to select the right Lightweight Cryptographic Algorithm (LWCA) for a given security requirement. To address this specific problem, an IoT Hardware Platform Security Advisor (IoT-HarPSecA) framework is proposed in this paper. The security framework is aimed at facilitating the choice of specific security algorithms given a set of security goals, hardware specifications, message payload size, application area, and energy requirement. Within the scope of this framework, we develop an easy-to-use tool in C++ that allows users to interact with the IoT-HarPSecA framework. The tool can potentially help non-security experts, such as electronics and computer engineers as well as application developers make informed decisions on selecting the appropriate security algorithms for their various applications. Finally, the paper presents some preliminary results and discussion. Musa G. Samaila, Moser Z. V. José, João B. F. Sequeiros, Mário M. Freire, Pedro R. M. Inácio |
ARES | 5 |
| 2018 | Security Threats and Possible Countermeasures in IoT Applications Covering Different Industry DomainsabstractThe world is witnessing the emerging role of Internet of Things (IoT) as a technology that is transforming different industries, global community and its economy. Currently a plethora of interconnected smart devices have been deployed for diverse pervasive applications and services, and billions more are expected to be connected to the Internet in the near future. The potential benefits of IoT include improved quality of life, convenience, enhanced energy efficiency, and more productivity. Alongside these potential benefits, however, come increased security risks and potential for abuse. Arguably, this is partly because many IoT start-ups and electronics hobbyists lack security expertise, and some established companies do not make security a priority in their designs, and hence they produce IoT devices that are often ill-equipped in terms of security. In this paper, we discuss different IoT application areas, and identify security threats in IoT architecture. We consider security requirements and present typical security threats for each of the application domains. Finally, we present several possible security countermeasures, and introduce the IoT Hardware Platform Security Advisor (IoT-HarPSecA) framework, which is still under development. IoT-HarPSecA is aimed at facilitating the design and prototyping of secure IoT devices. Musa G. Samaila, João B. F. Sequeiros, Mário M. Freire, Pedro R. M. Inácio |
ARES | 4 |
| 2018 | Approaches for optimizing virtual machine placement and migration in cloud environments: A survey
Manoel C. Silva Filho, Claudio C. Monteiro, Pedro R. M. Inácio, Mário M. Freire |
J. Parallel Distributed Comput. | 3 |
| 2017 | CloudSim Plus: A cloud computing simulation framework pursuing software engineering principles for improved modularity, extensibility and correctnessabstractCloud computing is an established technology to provide computing resources on demand that currently faces several challenges. Main challenges include management of shared resources, energy consumption, load balancing, resource provisioning and allocation, and fulfilment of service level agreements (SLAs). Due to its inherent complexity, cloud simulation is largely used to experiment new models and algorithms. This work presents CloudSim Plus, an open source simulation framework that pursues conformance to software engineering principles and object-oriented design in order to provide an extensible, modular and accurate tool. Based on the CloudSim framework, it aims to improve several engineering aspects, such as maintainability, reusability and extensibility. This work shows the benefits of CloudSim Plus, its particular features, how it ensures more accuracy, extension facility and usage simplicity. Manoel C. Silva Filho, Raysa L. Oliveira, Claudio C. Monteiro, Pedro R. M. Inácio, Mário M. Freire |
IM | 4 |
| 2017 | Applications of artificial immune systems to computer security: A survey
Diogo A. B. Fernandes, Mário M. Freire, Paulo A. P. Fazendeiro, Pedro R. M. Inácio |
J. Inf. Secur. Appl. | 4 |
| 2015 | Assessment of the Susceptibility to Data Manipulation of Android Games with In-app Purchases
Francisco Vigário, Diogo Fonseca, Mário M. Freire, Pedro R. M. Inácio |
SEC | 5 |
| 2013 | Secure user authentication in cloud computing management interfacesabstractThe degradation of the security of password-based mechanisms, combined with the increasing number of perils on the Internet, is rendering one-factor authentication outdated. This threatens the security of online operations for enterprises and end users, and consequently affects cloud computing solutions. Although cloud computing provides appealing benefits in terms of costs reduction, while increasing productivity, it introduces uncharted security issues (e.g., see [1]) beyond the ones inherited from the Internet. The emergence of mobile computing also makes authentication a priority, and has been reinforcing the need to build stronger and more resilient mechanisms; and simultaneously providing the means to develop new authentication mechanisms, namely Multi-Factor Authentication (MFA) schemes. The convergence to Single Sign-On (SSO) models is being used to eliminate or decrease password management complexity. MFA mostly appears in the form of Two-Factor Authentication (2FA) mechanisms based on One-Time Passwords (OTPs) for the second factor after standard password authentication. Such mechanisms can be based on public-key cryptography and may resort to several technologies to improve user experience, namely Quick Response (QR) codes, Short Message Service (SMSes), Trusted Platform Modules (TPMs), or even contactless Near Field Communication (NFC). Another trend leans to the adoption of risk-based authentication. Efforts for securing authentication are mainly being undertaken by the Initiative for Open AuTHentication (OATH) and the Fast IDentity Online (FIDO) alliance. Liliana F. B. Soares, Diogo A. B. Fernandes, Mário M. Freire, Pedro R. M. Inácio |
IPCCC | 4 |
| 2013 | Real-time traffic classification based on statistical tests for matching signatures with packet length distributionsabstractClassifying network traffic constitutes one of the most defying research topics nowadays. On the one hand, traffic classification is critical for assuring Quality of Service (QoS), the correct functioning and the security of the networks. On the other hand, the increasing complexity and throughput of networks, added to the problems caused by encryption and other evasive techniques, make of traffic classification a difficult and expensive task to perform. This paper describes a traffic classification in the dark mechanism based on matching several empirical distributions representing computer applications with the one of the target traffic. The classifier combines two methods for performing such matching in real-time and on a packet-by-packet manner: one based on the Kolmogorov-Smirnov test, and another one based on the Chi-Squared test. The experimental results included show that the mechanism is accurate and suitable for implementations demanding real-time operation. João V. P. Gomes, Mário M. Freire, Pedro R. M. Inácio |
LANMAN | 4 |
| 2013 | Identification of Peer-to-Peer VoIP Sessions Using Entropy and Codec PropertiesabstractVoice over Internet Protocol (VoIP) applications based on peer-to-peer (P2P) communications have been experiencing considerable growth in terms of number of users. To overcome filtering policies or protect the privacy of their users, most of these applications implement mechanisms such as protocol obfuscation or payload encryption that avoid the inspection of their traffic, making it difficult to identify its nature. The incapacity to determine the application that is responsible for a certain flow raises challenges for the effective management of the network. In this paper, a new method for the identification of VoIP sessions is presented. The proposed mechanism classifies the flows, in real-time, based on the speech codec used in the session. To make the classification lightweight, the behavioral signatures for each analyzed codec were created using only the lengths of the packets. Unlike most previous approaches, the classifier does not use the lengths of the packets individually. Instead, it explores their level of heterogeneity in real time, using entropy to emphasize such feature. The results of the performance evaluation show that the proposed method is able to identify VoIP sessions accurately and simultaneously recognize the used speech codec. João V. P. Gomes, Pedro R. M. Inácio, Manuela Pereira, Mário M. Freire, Paulo P. Monteiro |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2012 | Exploring Behavioral Patterns Through Entropy in Multimedia Peer-to-Peer TrafficabstractThe inclusion of encryption or evasive techniques in popular applications increased the importance of characterizing network traffic based on behavior. This study aims to characterize peer-to-peer (P2P) traffic from the perspective of host computers by focusing on the packet lengths. The article explores the dissimilarities between the lengths of Internet Protocol (IP) packets generated by P2P and non-P2P applications. The heterogeneity of those lengths was assessed using entropy and compared for different classes of applications, through the implementation of a sliding analysis window. Initial observations show that the lengths of the packets generated by P2P applications are more varied than those of non-P2P applications. These patterns were used to implement a method to identify hosts running P2P applications. Unlike previous studies on this area, we used the heterogeneity of the packet lengths instead of the length value per se, and a sliding window calculation procedure was adopted to allow real-time processing. The results of this study can be used for the characterization of traffic generated by P2P applications, as well as for traffic classification and management purposes. João V. P. Gomes, Pedro R. M. Inácio, Manuela Pereira, Mário M. Freire, Paulo P. Monteiro |
Comput. J. | 2 |
| 2012 | Corrigendum: Exploring Behavioral Patterns Through Entropy in Multimedia Peer-to-Peer Trafficabstractdoi: 10.1093/comjnl/bxr127 Comp J 2012;55(6): 740–755 In the above article, on page 751, the image used for Figure 7 was incorrect. The image should have been: João V. P. Gomes, Pedro R. M. Inácio, Manuela Pereira, Mário M. Freire, Paulo P. Monteiro |
Comput. J. | 2 |
| 2011 | On-line Detection of Encrypted Traffic Generated by Mesh-Based Peer-to-Peer Live Streaming Applications: The Case of GoalBitabstractThe number and popularity of applications developed over the Peer-to-Peer (P2P) network paradigm has been growing over the last decade, some of which are dedicated to streaming multimedia content. To deceive traffic shaping mechanisms or improve the security of the communications, these applications generate encrypted traffic or resort to several obfuscation techniques, making it difficult to manage this kind of traffic at the network level. In this work, we propose a method that explores transmission vulnerabilities of the encrypted traffic allowing its detection. Hence, an experimental test bed was created to capture a diversity of traffic, which includes flows of a widely used P2P media streaming application called Goal Bit. The collected traces of traffic were then analysed, and a set of rules was created for the SNORT network intrusion detection system, which allows the successful detection of the encrypted traffic generated by Goal Bit. The accuracy of this system was then validated experimentally. André F. Esteves, Pedro R. M. Inácio, Manuela Pereira, Mário M. Freire |
NCA | 2 |
| 2010 | NetOdyssey - A New Tool for Real-Time Analysis of Network TrafficabstractTraffic monitoring and analysis is of critical importance for managing and designing modern computer networks, and constitutes nowadays a very active research field. In most of their studies, researchers use techniques and tools that follow a statistical approach to obtain a deeper knowledge about the traffic behaviour. Network administrators also find great value in statistical analysis tools. Many of those tools return similar metrics calculated for common properties of network packets. This paper presents NetOdyssey, a new tool for the statistical analysis of network traffic. It is able to capture the traffic from the network card or from a pre-collected trace, and generates several statistics calculated for different traffic properties in separate threads. Its modular architecture allows one to adapt NetOdyssey to specific analysis purposes, resorting to the possibility to easily implement custom-made modules, whose implementation principles are also described in here. Fábio D. Beirão, João V. P. Gomes, Pedro R. M. Inácio, Manuela Pereira, Mário M. Freire |
NCA | 3 |
| 2010 | Source traffic analysisabstractTraffic modeling and simulation plays an important role in the area of Network Monitoring and Analysis, for it provides practitioners with efficient tools to evaluate the performance of networks and of their elements. This article focus on the traffic generated by a single source, providing an overview of what was done in the field and studying the statistical properties of the traffic produced by a personal computer, including analysis of the autocorrelation structure. Different distributions were fitted to the interarrival times, packet sizes, and byte count processes with the goal of singling out the ones most suitable for traffic generation. João V. P. Gomes, Pedro R. M. Inácio, Branka Lakic, Mário M. Freire, Henrique J. A. da Silva, Paulo P. Monteiro |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2009 | The design and evaluation of the Simple Self-Similar Sequences Generator
Pedro R. M. Inácio, Branka Lakic, Mário M. Freire, Manuela Pereira, Paulo P. Monteiro |
Inf. Sci. | 1 |
| 2008 | Analysis of Peer-to-Peer Traffic Using a Behavioural Method Based on EntropyabstractThe increasing number of applications offering their services over peer-to-peer (P2P) platforms is changing the properties of the traffic within computer networks. Their massive use raises a few imperative challenges for network administrators and Internet service providers, regarding the quality of service and security of their networks. It such scenario, it is important to develop mechanisms to control and efficiently manage the P2P traffic and prepare the networks to support it, for which it is necessary to study the effect of P2P applications in the traffic of computer networks and to develop methodologies to characterise its behaviour. In this paper, the characteristics of the traffic generated by P2P applications are analysed from the behavioural point of view, and entropy is used to measure the heterogeneity embedded in the packet sizes. The results obtained show evident difference between P2P and non-P2P traffic, being the proposed approach applicable to real-time and high-speed networks with encrypted P2P traffic, where the existing methodologies are useless. João V. P. Gomes, Pedro R. M. Inácio, Mário M. Freire, Manuela Pereira, Paulo P. Monteiro |
IPCCC | 2 |