Pablo Fernández Saura

dblp:298/7896 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0003-2042-3070ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Enhancing federated intrusion detection through LLM-Driven alert enrichment and collaborative threat information sharing
Pablo Fernández Saura, Jorge Bernal Bernabé, Antonio F. Skarmeta
Future Gener. Comput. Syst.1
2026 Automating 5G Traffic Generation With Virtual UEs: A Scalable Network Testing Infrastructure
abstract
5G technology represents a transformative leap in wireless networks, promising advancements in smart cities, autonomous transport, and IoT through high data speeds, reduced latency, and support for numerous devices. However, realizing these benefits requires overcoming significant security challenges, particularly in anomaly detection, as the vast device flow increases the risk of vulnerabilities. While AI is critical for this task, the availability of models for AI-based 5G analysis remains limited. This paper addresses this gap by presenting a scalable research framework for generating realistic 5G traffic across both control and user planes without actual 5G devices. The framework enables non-5G devices, such as mobile phones or PCs, to connect to a real 5G RAN infrastructure via virtual User Equipments (UEs), allowing them to generate client traffic at reduced costs and without physical 5G devices. This innovative approach supports the generation of large amounts of 5G traffic, for subsequent collection and analysis to create various datasets, simulating diverse network behaviours for cybersecurity purposes. By leveraging this virtualized environment, our framework offers a versatile, cost-effective solution for comprehensive 5G data generation in a controlled setting. Results demonstrate that 5G traffic generated by non-5G devices through this framework is suitable for AI modelling and training, advancing research capabilities in anomaly detection and overall network security.
Emilio Garcia de La Calera Molina, Anthony Joel Pogo Medina, Alejandro Molina Zarca, Pablo Fernández Saura, Antonio F. Skarmeta
IEEE Trans. Netw. Serv. Manag.4
2025 On Automating Security Policies with Contemporary LLMs (Short Paper)
abstract
The complexity of modern computing environments and the growing sophistication of cyber threats necessitate a more robust, adaptive, and automated approach to security enforcement. In this paper, we present a framework leveraging large language models (LLMs) for automating attack mitigation policy compliance through an innovative combination of in-context learning and retrieval-augmented generation (RAG). We begin by describing how our system collects and manages both tool and API specifications, storing them in a vector database to enable efficient retrieval of relevant information. We then detail the architectural pipeline that first decomposes high-level mitigation policies into discrete tasks and subsequently translates each task into a set of actionable API calls. Our empirical evaluation, conducted using publicly available CTI policies in STIXv2 format and Windows API documen-tation, demonstrates significant improvements in precision, recall, and Fl-score when employing RAG compared to a non-RAG baseline.
Pablo Fernández Saura, K. R. Jayaram, Vatche Isahagian, Jorge Bernal Bernabé, Antonio F. Skarmeta
SSE1
2025 The Resilmesh Architecture: Situation Aware Enabled Cyber Resilience for Dispersed, Heterogenous Cyber Systems
abstract
Cyber systems (CyS) are becoming more and more complex as they are comprised of several infrastructure layers, heterogeneous technologies and dispersed deployments over wide geographical areas (cloud/edge/endpoint) that facilitates multiple attack entry points (vectors). At the same time, CyS attacks are constantly evolving and have become more complex and sophisticated. To address these issues, the ResilMesh architecture aims to provide critical infrastructure security teams with a greater cyber resilience capability by improving cyber resilience using Cyber Situational Awareness (CSA) based security orchestration and analytics framework. The framework enables organizations to achieve real-time defense, reducing attack surface impact by developing tools to combat complexity, disperse infrastructure, delivering flexible placement of security controls across the CyS infrastructure. The architecture combats Advanced Persistent Threat (APT) sophistication by leveraging advanced AI algorithms and tools for early and ongoing attack detection and prediction and improved situation. This paper presents the Resilmesh architecture, a first PoC implementation, as well as an evaluation of the Resilmesh capabilities to detect and mitigate APTs.
Jorge Bernal Bernabé, Martin Husák, Lukás Sadlek, Branka Stojanovic, Michael Somma, Jorgeley Inacio de Oliveira, Ekam Puri Nieto, Pablo Fernández Saura, Antonio F. Skarmeta, Vinh Hoa La
NetSoft9
2025 Ai-Based Meta-Orchestration for Fl-Based Anomaly Detection in B5g Networks
abstract
G networks will need to handle Multi-domain, multi-tenant and multi-operator scenarios where the security orchestration of services and network functions will face high complexity of scalability, interoperability and security. In particular, 6G networks will need to manage AI-based network functions to support analytics that can be encapsulated as virtual functions that need to be dynamically orchestrated, configured, deployed, decommissioned, migrated and reconfigured on demand. The distributed nature of these scenarios requires a federated learning FL approach to handle AI-based collaborative learning where FL-agents can be deployed in the continuum of any network segment of the network. This paper proposes an AI-based meta-orchestration approach for multi-domain and multi-tenant 6 G deployments intended to choreograph the FLbased AI functions. The meta-Orchestration encompasses diverse phases, including selection of the orchestration strategy, the orchestration graph building and the selection of best AI-based orchestration algorithm depending on the actual context, thereby maximizing the effectiveness of the allocation of the FL-agents. The implementation and performance evaluation to orchestrate FL agents with diverse AI-based algorithms across the continuum proves our approach to detect anomalies using FL in distributed scenarios.
Pablo Fernández Saura, José Manuel Bernabé Murcia, Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta
NetSoft1
2023 Intrusion Detection Based on Privacy-Preserving Federated Learning for the Industrial IoT
abstract
Federated learning (FL) has attracted significant interest given its prominent advantages and applicability in many scenarios. However, it has been demonstrated that sharing updated gradients/weights during the training process can lead to privacy concerns. In the context of the Internet of Things (IoT), this can be exacerbated due to intrusion detection systems (IDSs), which are intended to detect security attacks by analyzing the devices’ network traffic. Our work provides a comprehensive evaluation of differential privacy techniques, which are applied during the training of an FL-enabled IDS for industrial IoT. Unlike previous approaches, we deal with nonindependent and identically distributed data over the recent ToN_IoT dataset, and compare the accuracy obtained considering different privacy requirements and aggregation functions, namely FedAvg and the recently proposed Fed+. According to our evaluation, the use of Fed+ in our setting provides similar results even when noise is included in the federated training process.
Pedro Ruzafa Alcazar, Pablo Fernández Saura, Enrique Mármol Campos, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Antonio F. Skarmeta
IEEE Trans. Ind. Informatics2
2022 Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challenges
abstract
The application of Machine Learning (ML) techniques to the well-known intrusion detection systems (IDS) is key to cope with increasingly sophisticated cybersecurity attacks through an effective and efficient detection process. In the context of the Internet of Things (IoT), most ML-enabled IDS approaches use centralized approaches where IoT devices share their data with data centers for further analysis. To mitigate privacy concerns associated with centralized approaches, in recent years the use of Federated Learning (FL) has attracted a significant interest in different sectors, including healthcare and transport systems. However, the development of FL-enabled IDS for IoT is in its infancy, and still requires research efforts from various areas, in order to identify the main challenges for the deployment in real-world scenarios. In this direction, our work evaluates a FL-enabled IDS approach based on a multiclass classifier considering different data distributions for the detection of different attacks in an IoT scenario. In particular, we use three different settings that are obtained by partitioning the recent ToN_IoT dataset according to IoT devices’ IP address and types of attack. Furthermore, we evaluate the impact of different aggregation functions according to such setting by using the recent IBMFL framework as FL implementation. Additionally, we identify a set of challenges and future directions based on the existing literature and the analysis of our evaluation results.
Enrique Mármol Campos, Pablo Fernández Saura, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Gianmarco Baldini, Antonio F. Skarmeta
Comput. Networks2