VLDB 2026 Research / reviewers in the wild / expert
Pedro Horchulhack
dblp:298/9962
· DBLP profile ↗
11ranked-venue papers
5as first author
11since 2021 · last 2024
0009-0002-3036-0210ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Non-interactive One-Time Password-Based Method to Enhance the Vault Security
Juarez Oliveira, Altair Olivo Santin, Eduardo Viegas 0001, Pedro Horchulhack |
AINA (4) | 4 |
| 2024 | Toward a Reliable Network-Based Intrusion Detection Model for SCADA: A Classification with Reject Option ApproachabstractIndustrial control systems (ICS) are often targeted by highly motivated attackers seeking to disrupt their services due to its critical nature. Traditional cybersecurity does not provide the necessary reliability for ICS systems. Even when implemented with many layers of defense, including network intrusion detection systems (NIDS). This paper proposes a dynamic and reliable intrusion detection model that is implemented in two steps. First, it proactively classifies each type of possible network attack on the basis of the current network traffic behavior. Second, it evaluates the classification quality through rejection option, which is an indication of its reliability. By adapting to the evolving network traffic, our proposal increases the system robustness against motivated attackers. The proposed model effectiveness has been demonstrated by experimenting in a controlled testbed with more than 14 attack categories. The dynamic selection of security mechanisms allowed us to increase the detection accuracy by up to 26%. Moreover, the classification evaluation in the proposed model achieves up to 99% detection accuracy with only 1% rejection. Paulo Roberto de Oliveira, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Everton de Matos |
IJCNN | 4 |
| 2024 | Network-based Intrusion Detection Through Image-based CNN and Transfer LearningabstractMachine learning (ML) techniques for network intrusion detection is still limited in production environments despite promising results reported in the literature. Network traffic behavior exhibits considerable variability and evolves over time, requiring periodic model updates. This paper proposes a new approach to intrusion detection modeling based on CNN and transfer learning to reduce updating overhead. Its implementation is twofold. First, CNN is implemented using flow-based feature expansion derived from neural flattened hyperdimensional space. This expanded space representation contributes to a longer model lifetime and maintains system accuracy over time. Second, the required training data and computational cost are significantly reduced by performing periodic model updates based on a transfer learning approach. Experiments on a novel dataset with over 2.6 TB of data and one year of real-world network traffic demonstrate the feasibility of the proposal. Our proposal improves the average F1 score by up to 0.19 when no model updates are performed. While improving the system’s accuracy, model updates impose only 42.8% of the computational cost. Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, João A. Simioni |
IWCMC | 1 |
| 2024 | Detection of quality of service degradation on multi-tenant containerized services
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Felipe Ramos, Pietro Tedeschi |
J. Netw. Comput. Appl. | 1 |
| 2023 | Towards a Reliable Hierarchical Android Malware Detection Through Image-based CNNabstractThe number of Android malicious applications keeps growing as time passes, even paving their way to official app markets. In recent years, a promising malware detection approach makes use of the compiled app source codes (dex), through convolutional neural networks (CNN) as an image classification task. Unfortunately, current proposals often rely on unrealistic datasets, focusing their detection on the mal-ware families, while neglecting the detection of malware apps in the first place. In this paper, we propose a reliable and hierarchical Android malware detection through an image-based CNN scheme, implemented twofold. First, Android malware classification is performed in a hierarchically-structured local manner, initially identifying malware apps, then, their related family. Second, to ensure reliability and improve classification accuracy, only highly confident classified apps are reported, in a classification with reject option rationale. Experiments performed in a new dataset with over 26 thousand Android apps, divided into 29 malware families, compounding over 13 GB of app dex images, have shown that current image-based CNN for malware detection is unable to provide high detection accuracies. In contrast, our proposed model is able to reliably detect malware apps, improving the true-negative rates by up to 5.5%, and the average true-positive rate of the malware families of accepted apps by up to 12.7%, while rejecting only 10% of Android apps. Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack |
CCNC | 5 |
| 2023 | A Dynamic Network-based Intrusion Detection Model for Industrial Control SystemsabstractIndustrial Control Systems (ICS) play a crucial role in managing and controlling industrial assets. Due to their critical importance, adversaries are often highly motivated to target these systems, as a successful attack can disrupt the entire industry’s operations. In general, to improve the system’s security, proposed intrusion detection schemes often resort to traditional security mechanisms. As a consequence, due to their static nature, attackers can easily evade designed detection approaches. In light of this, this paper proposes a new dynamic network-based intrusion detection model for ICS, implemented in two phases. First, our scheme extracts network-related features to describe the current ICS environment behavior. Second, the security mechanisms are proactively selected based on the extracted network traffic behavior. As a result, our scheme can adjust the system’s configuration based on the current assessed event. Experiments on a new dataset, featuring over 14 attack categories targeting a SCADA system revealed that traditional detection methods face challenges in handling diverse attack categories. Conversely, our proposed model improved the average true-positive rates by up to 20% while also improving the range of detected attacks. Paulo Roberto de Oliveira, Altair Olivo Santin, Pedro Horchulhack, Eduardo Viegas 0001, Everton de Matos |
TrustCom | 3 |
| 2022 | Detection of Service Provider Hardware Over-commitment in Container Orchestration EnvironmentsabstractThe deployment of container-based services continues to increase as time passes, mainly due to its fast provision time and lower allocation overheads. Yet, the literature still neglects the performance degradation in containers due to multi-tenancy and service provider hardware over-commitment. This paper proposes a new hardware over-commitment detection for container orchestration environments, implemented twofold. First, the containerized hardware usage of deployed containers is continuously monitored in a non-intrusive manner, leveraging the container engine resource management interface. Second, collected features are used by a recurrent neural network model for detecting both container and service level hardware over-commitment, following a time-series rationale. Experiments run on a containerized Apache Spark distribution have shown that multi-tenancy and hardware over-commitment significantly affect its performance. In addition, our proposed model is able to detect hardware over-commitment with up to 91% of true-positive at the container level, and up to 93% true-positive at the service level. Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin |
GLOBECOM | 1 |
| 2022 | Intrusion Detection Model Updates Through GAN Data Augmentation and Transfer LearningabstractCurrent machine learning techniques for network-based intrusion detection cannot handle the evolving behavior of network traffic, requiring periodic model updates to be conducted. Besides requiring huge amounts of labeled network traffic to be provided, traditional model updates demand expressive computational costs. This paper proposes a new feasible model update procedure implemented in two steps. First, we use a Generative Adversarial Network (GAN) to augment the sampled network traffic. Next, we use the augmented dataset to perform model updates through a transfer learning-based approach. Thus, our model can decrease both the number of instances that must be labeled and the computational costs during model updates. Our experiments on a one-year dataset with over 8 TB of data show that literature techniques cannot handle changes in network traffic behavior. In contrast, the proposed model without updates improved true-positive rates by up to 25.6%. With monthly model updates, it requires only 14% of computational costs and 2.3% of instances to be provided. Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Jhonatan Geremias |
GLOBECOM | 1 |
| 2022 | Towards Multi-view Android Malware Detection Through Image-based Deep LearningabstractOver the last years, several works have proposed highly accurate Android malware detection techniques. Surprisingly, modern malware apps can still pave their way to official markets, thus, demanding the provision of more robust and accurate detection approaches. This paper proposes a new multi-view Android malware detection through image-based deep learning, implemented threefold. First, apps are evaluated according to several feature sets in a multi-view setting, thus, increasing the information provided for the classification task. Second, extracted feature sets are converted to an image format while maintaining the principal components of the data distribution, keeping the information for the classification task. Third, built images are jointly represented in a single shot, each in a predefined image channel, enabling the application of deep learning architectures. Experiments on a new version of a publicly available Android malware dataset composed of over 11 thousand Android apps have shown our proposal's feasibility. It reaches true-negative rates of up to 99.5% when implemented with a single-view approach with our new image-building technique. In addition, if our proposed multi-view scheme is used, the classification accuracies of malware families become more stable, reaching a true-positive rate of up to 98.7%. Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack |
IWCMC | 5 |
| 2022 | Toward feasible machine learning model updates in network-based intrusion detection
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin |
Comput. Networks | 1 |
| 2021 | A Machine Learning Model for Detection of Docker-based APP Overbooking on KubernetesabstractResource allocation overbooking is an approach used by cloud providers that allocates more virtual resources than available on physical hardware, which may imply service quality degradation. Docker in cloud computing environments is being increasingly used due to their fast provisioning and deployment, while the impact of overbooking of resources allocation due to multi-tenancy remains overlooked. This paper proposes a machine learning model to detect overbooking in Kubernetes environments within the docker container. The proposed model continuously monitors distributed container OS usage and application performance metrics. The collected metrics are used as input to a machine learning model that identifies multi-tenancy interference incurring in application performance degradation. Experiments performed on a Kubernetes cluster with a Docker-based Big Data processing application showed that our proposed model could detect resource overbooking with up to 98% accuracy. This implies an overbooking on a resource of up to 1.2 in the client’s domain. Felipe Ramos, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Roger Robson dos Santos, Allan Espindola |
ICC | 4 |