VLDB 2026 Research / reviewers in the wild / expert
Vanesa Daza
dblp:29/4405
· DBLP profile ↗
25ranked-venue papers
10as first author
7since 2021 · last 2026
0000-0003-0583-7929ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 6 first-author · 3 since 2021Computer networks · 7 · 2 first-author · 3 since 2021Theory of computation · 4 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A knowledge-based multi-agent framework for security control recommendationabstractHardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise. In this regard, Decision Support Systems (DSS) with embedded expert knowledge can assist users by guiding them with security recommendations to meet their objectives. This work proposes a Security DSS that recommends security control sub-families given minimal user requirements indicating coverage of different security dimensions. It leverages a curated, unified dataset from both well-known Information Security (InfoSec) and academic sources. This DSS is defined as a non-zero-sum, simultaneous game that is grounded in a Multi-Agent Influence Diagram (MAID) model and explores the decision space over 7 security dimensions or agents, using no-regret online learning to ultimately find the security control sub-families that best fit the requirements while incurring minimal under- and over-provisioning of security resources. This work was validated in terms of performance and accuracy, among others, for varying dataset sizes. It shows exceptional satisfaction coverage results of 99% when using as little as ∼ 65% of the SW-implementable security controls, running in 1.2–35.7 seconds; and more moderate coverage results of 73%–77% when using ∼ 29% of the controls, resolving in 0.8–13.8 seconds. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
Knowl. Based Syst. | 3 |
| 2025 | A Bayesian Network Approach for Enhancing Security-Focused Decision Support SystemsabstractThe adoption and integration of heterogeneous stacks in most of today’s open-source based networks brings clear benefits like interoperability and availability of advanced features. Yet, on the other hand the increasing number of interconnecting components and moving parts requires maintaining an ever increasing base of interdisciplinary knowledge of different tools in different domains to ensure proper operation. To alleviate such efforts, this work proposes a Decision Support System (DSS) to guide infrastructure operators through the selection of security approaches (e.g. tools) to adopt in their environments. This framework easily captures the end-user high-level requirements on the security triad for different domains and runs inference on the designated models to provide the identified tools (security mechanisms) that better serve such needs. The presented DSS aims at delivering an understandable and extensible framework to accommodate varying requirements and Bayesian Network (BN) models. The architecture and modelling of the system are proposed, aligned with its theoretical framework. Its performance is evaluated in terms of time and prediction accuracy. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
LCN | 3 |
| 2024 | A Blockchain-Based Decentralized and Incentive Compatible Distributed Computing ProtocolabstractWe outline Marvel DC, a fully decentralized blockchain-based distributed-computing protocol which guarantees that computers are strictly incentivized to correctly perform requested computations. Marvel DC utilizes a reputation management protocol to ensure that, for any minority of computers not performing calculations correctly, these computers are identified and selected for computations with diminishing probability. We then outline Privacy Marvel DC, a privacy-enhanced version of Marvel DC which decouples results from the computers which computed them, making the protocol suitable for computations such as Federated Learning, where results can reveal sensitive information about that computer that computed them. Conor McMenamin, Vanesa Daza |
ICBC | 2 |
| 2024 | Private, Anonymous, Collateralizable Commitments vs. MEVabstractIn this work, we introduce the private, anonymous, collateralizable commitments (PACCs) framework. PACCs allow any smart contract wallet holder to collateralize a claim, request, or commitment in general, in a private and anonymous manner. PACCs can prove arbitrarily much or little about the wallet generating the commitment, and/or the transaction which is being committed. We demonstrate that PACCs can be applied to effectively eliminate maximal-extractable value (MEV) in DeFi where it currently occurs, shifting MEV instead to censorship. Conor McMenamin, Vanesa Daza |
ICBC | 2 |
| 2022 | Clover: An anonymous transaction relay protocol for the bitcoin P2P networkabstractAbstract The Bitcoin P2P network currently represents a reference benchmark for modern cryptocurrencies. Its underlying protocol defines how transactions and blocks are distributed through all participating nodes. To protect user privacy, the identity of the node originating a message is kept hidden. However, an adversary observing the whole network can analyze the spread pattern of a transaction to trace it back to its source. This is possible thanks to the so-called rumor centrality, which is caused by the symmetry in the spreading of gossip-like protocols. Recent works try to address this issue by breaking the symmetry of the Diffusion protocol, currently used in Bitcoin, and leveraging proxied broadcast. Nonetheless, the complexity of their design can be a barrier to their adoption in real life. In this work, we propose Clover, a novel transaction relay protocol that protects the source of transaction messages with a simple, yet effective, design. Compared to previous solutions, our protocol does not require building propagation graphs, and reduces the ability of the adversary to gain precision by opening multiple connections towards the same node. Experimental results show that the deanonymization accuracy of an eavesdropper adversary against Clover is up to 10 times smaller compared to Diffusion. Federico Franzoni, Vanesa Daza |
Peer-to-Peer Netw. Appl. | 2 |
| 2022 | AToM: Active topology monitoring for the bitcoin peer-to-peer networkabstractAbstract Over the past decade, the Bitcoin P2P network protocol has become a reference model for all modern cryptocurrencies. While nodes in this network are known, the connections among them are kept hidden, as it is commonly believed that this helps protect from deanonymization and low-level attacks. However, adversaries can bypass this limitation by inferring connections through side channels. At the same time, the lack of topology information hinders the analysis of the network, which is essential to improve efficiency and security. In this paper, we thoroughly review network-level attacks and empirically show that topology obfuscation is not an effective countermeasure. We then argue that the benefits of an open topology potentially outweigh its risks, and propose a protocol to reliably infer and monitor connections among reachable nodes of the Bitcoin network. We formally analyze our protocol and experimentally evaluate its accuracy in both trusted and untrusted settings. Results show our system has a low impact on the network, and has precision and recall are over 90% with up to 20% of malicious nodes in the network. Federico Franzoni, Xavier Salleras, Vanesa Daza |
Peer-to-Peer Netw. Appl. | 3 |
| 2021 | Achieving state machine replication without honest playersabstractExisting standards for player characterisation in tokenised state machine replication protocols depend on honest players who will always follow the protocol, regardless of possible token increases for deviating. Given the ever-increasing market capitalisation of these tokenised protocols, honesty is becoming more expensive and more unrealistic. As such, this out-dated player characterisation must be removed to provide true guarantees of safety and liveness in a major stride towards universal trust in state machine replication protocols and a new scale of adoption. As all current state machine replication protocols are built on these legacy standards, it is imperative that a new player model is identified and utilised to reflect the true nature of players in tokenised protocols, now and into the future. Conor McMenamin, Vanesa Daza, Matteo Pontecorvi |
AFT | 2 |
| 2020 | SANS: Self-Sovereign Authentication for Network Slicesabstract5G communications proposed significant improvements over 4G in terms of efficiency and security. Among these novelties, the 5G network slicing seems to have a prominent role: deploy multiple virtual network slices, each providing a different service with different needs and features. Like this, a Slice Operator (SO) ruling a specific slice may want to offer a service for users meeting some requirements. It is of paramount importance to provide a robust authentication protocol, able to ensure that users meet the requirements, providing at the same time a privacy-by-design architecture. This makes even more sense having a growing density of Internet of Things (IoT) devices exchanging private information over the network. In this paper, we improve the 5G network slicing authentication using a Self-Sovereign Identity (SSI) scheme: granting users full control over their data. We introduce an approach to allow a user to prove his right to access a specific service without leaking any information about him. Such an approach is SANS, a protocol that provides nonlinkable protection for any issued information, preventing an SO or an eavesdropper from tracking users’ activity and relating it to their real identities. Furthermore, our protocol is scalable and can be taken as a framework for improving related technologies in similar scenarios, like authentication in the 5G Radio Access Network (RAN) or other wireless networks and services. Such features can be achieved using cryptographic primitives called Zero-Knowledge Proofs (ZKPs). Upon implementing our solution using a state-of-the-art ZKP library and performing several experiments, we provide benchmarks demonstrating that our approach is affordable in speed and memory consumption. Xavier Salleras, Vanesa Daza |
Secur. Commun. Networks | 2 |
| 2017 | CONNECT: CONtextual NamE disCovery for blockchain-based services in the IoTabstractThe Internet of Things is gaining momentum thanks to the provided vision of seamlessly interconnected devices. However, a unified way to discover and to interact with the surrounding smart environment is missing. As an outcome, we have been assisting to the development of heterogeneous ecosystems, where each service provider adopts its own protocol- thus preventing IoT devices from interacting when belonging to different providers. And, the same is happening again for the blockchain technology which provides a robust and trusted way to accomplish tasks -unfortunately not providing interoperability thus creating the same heterogeneous ecosystems above highlighted. In this context, the fundamental research question we address is how do we find things or services in the Internet of Things. In this paper, we propose the first IoT discovery approach which provides an answer to the above question by exploiting hierarchical and universal multi-layered blockchains. Our approach does neither define new standards nor force service providers to change their own protocol. On the contrary, it leverages the existing and publicly available information obtained from each single blockchain to have a better knowledge of the surrounding environment. The proposed approach is detailed and discussed with the support of relevant use cases. Vanesa Daza, Roberto Di Pietro, Ivan Klimek, Matteo Signorini |
ICC | 1 |
| 2017 | Designing Fully Secure Protocols for Secure Two-Party Computation of Constant-Domain Functions
Vanesa Daza, Nikolaos Makriyannis |
TCC (1) | 1 |
| 2016 | FRoDO: Fraud Resilient Device for Off-Line Micro-PaymentsabstractCredit and debit card data theft is one of the earliest forms of cybercrime. Still, it is one of the most common nowadays. Attackers often aim at stealing such customer data by targeting the Point of Sale (for short, PoS) system, i.e. the point at which a retailer first acquires customer data. Modern PoS systems are powerful computers equipped with a card reader and running specialized software. Increasingly often, user devices are leveraged as input to the PoS. In these scenarios, malware that can steal card data as soon as they are read by the device has flourished. As such, in cases where customer and vendor are persistently or intermittently disconnected from the network, no secure on-line payment is possible. This paper describes FRoDO, a secure off-line micro-payment solution that is resilient to PoS data breaches. Our solution improves over up to date approaches in terms of flexibility and security. To the best of our knowledge, FRoDO is the first solution that can provide secure fully off-line payments while being resilient to all currently known PoS breaches. In particular, we detail FRoDO architecture, components, and protocols. Further, a thorough analysis of FRoDO functional and security properties is provided, showing its effectiveness and viability. Vanesa Daza, Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2014 | FORCE - Fully Off-line secuRe CrEdits for Mobile Micro PaymentsabstractPayment schemes based on mobile devices are expected to supersede traditional electronic payment approaches in the next few years. However, current solutions are limited in that protocols require at least one of the two parties to be on-line, i.e. connected either to a trusted third party or to a shared database. Indeed, in cases where customer and vendor are persistently or intermittently disconnected from the network, any on-line payment is not possible. This paper introduces FORCE, a novel mobile micro payment approach where all involved parties can be fully off-line. Our solution improves over state-of-the-art approaches in terms of payment flexibility and security. In fact, FORCE relies solely on local data to perform the requested operations. Present paper describes FORCE architecture, components and protocols. Further, a thorough analysis of its functional and security properties is provided showing its effectiveness and viability. Vanesa Daza, Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
SECRYPT | 1 |
| 2014 | Performance analysis of a Multiuser Multi-Packet Transmission system for WLANs in non-saturation conditions
Boris Bellalta, Azadeh Faridi, Jaume Barceló, Vanesa Daza, Miquel Oliver |
Comput. Networks | 4 |
| 2009 | Flaws in some self-healing key distribution schemes with revocation
Vanesa Daza, Javier Herranz, Germán Sáez |
Inf. Process. Lett. | 1 |
| 2008 | On the Computational Security of a Distributed Key Distribution SchemeabstractIn a distributed key distribution scheme, a set of servers help a set of users in a group to securely obtain a common key. Security means that an adversary who corrupts some servers and some users has no information about the key of a non-corrupted group. In this work we formalize the security analysis of one of such schemes \\cite{DHPS02}, which was not considered in the original proposal. We prove the scheme secure in the random oracle model, assuming that the Decisional Diffie-Hellman problem is hard to solve. We also detail a possible modification of that scheme and the one in \\cite{NPR99}, which allows to prove the security of the schemes without assuming that a specific hash function behaves as a random oracle. As usual, this improvement in the security of the schemes is at the cost of an efficiency loss. Vanesa Daza, Javier Herranz, Germán Sáez |
IEEE Trans. Computers | 1 |
| 2008 | On Codes, Matroids, and Secure Multiparty Computation From Linear Secret-Sharing SchemesabstractError-correcting codes and matroids have been widely used in the study of ordinary secret sharing schemes. In this paper, the connections between codes, matroids, and a special class of secret sharing schemes, namely, multiplicative linear secret sharing schemes (LSSSs), are studied. Such schemes are known to enable multiparty computation protocols secure against general (nonthreshold) adversaries. Two open problems related to the complexity of multiplicative LSSSs are considered in this paper. The first one deals with strongly multiplicative LSSSs. As opposed to the case of multiplicative LSSSs, it is not known whether there is an efficient method to transform an LSSS into a strongly multiplicative LSSS for the same access structure with a polynomial increase of the complexity. A property of strongly multiplicative LSSSs that could be useful in solving this problem is proved. Namely, using a suitable generalization of the well-known Berlekamp-Welch decoder, it is shown that all strongly multiplicative LSSSs enable efficient reconstruction of a shared secret in the presence of malicious faults. The second one is to characterize the access structures of ideal multiplicative LSSSs. Specifically, the considered open problem is to determine whether all self-dual vector space access structures are in this situation. By the aforementioned connection, this in fact constitutes an open problem about matroid theory, since it can be restated in terms of representability of identically self-dual matroids by self-dual codes. A new concept is introduced, the flat-partition, that provides a useful classification of identically self-dual matroids. Uniform identically self-dual matroids, which are known to be representable by self-dual codes, form one of the classes. It is proved that this property also holds for the family of matroids that, in a natural way, is the next class in the above classification: the identically self-dual bipartite matroids. Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jiménez Urroz, Gregor Leander, Jaume Martí-Farré, Carles Padró |
IEEE Trans. Inf. Theory | 2 |
| 2007 | An Incentive-Based System for Information Providers over Peer-to-Peer Mobile Ad-Hoc Networks
Jordi Castellà-Roca, Vanesa Daza, Josep Domingo-Ferrer, Jesús A. Manjón, Francesc Sebé, Alexandre Viejo |
MDAI | 2 |
| 2007 | CCA2-Secure Threshold Broadcast Encryption with Shorter Ciphertexts
Vanesa Daza, Javier Herranz, Paz Morillo, Carla Ràfols |
ProvSec | 1 |
| 2007 | Cryptographic techniques for mobile ad-hoc networks
Vanesa Daza, Javier Herranz, Paz Morillo, Carla Ràfols |
Comput. Networks | 1 |
| 2007 | A distributed architecture for scalable private RFID tag identification
Agusti Solanas, Josep Domingo-Ferrer, Antoni Martínez-Ballesté, Vanesa Daza |
Comput. Networks | 4 |
| 2005 | On Codes, Matroids and Secure Multi-party Computation from Linear Secret Sharing Schemes
Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jiménez Urroz, Gregor Leander, Jaume Martí-Farré, Carles Padró |
CRYPTO | 2 |
| 2004 | Bounds and constructions for unconditionally secure distributed key distribution schemes for general access structures
Carlo Blundo, Paolo D'Arco, Vanesa Daza, Carles Padró |
Theor. Comput. Sci. | 3 |
| 2003 | Constructing General Dynamic Group Key Distribution Schemes with Decentralized User Join
Vanesa Daza, Javier Herranz, Germán Sáez |
ACISP | 1 |
| 2002 | A Distributed and Computationally Secure Key Distribution Scheme
Vanesa Daza, Javier Herranz, Carles Padró, Germán Sáez |
ISC | 1 |
| 2001 | Bounds and Constructions for Unconditionally Secure Distributed Key Distribution Schemes for General Access Structures
Carlo Blundo, Paolo D'Arco, Vanesa Daza, Carles Padró |
ISC | 3 |