VLDB 2026 Research / reviewers in the wild / expert
Nerea Toledo
dblp:45/10099
· DBLP profile ↗
17ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-9394-1269ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-authorSecurity and privacy · 5 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reinforcement Learning in action: Powering intelligent intrusion responses to advanced cyber threats in realistic scenariosabstractGiven the increasing incidence of sophisticated cyber-attacks, particularly Advanced Persistent Threats (APTs), there is a growing need for intelligent and adaptive intrusion response solutions. In this paper, we propose a Reinforcement Learning (RL)-based model for APT intrusion response that can manage dynamic, multi-stage attacks and large observation spaces. The model supports both policy-based and value-based learning approaches, enabling comparative evaluation between different strategies. We introduce a realistic RL training environment based on emulation infrastructure, which accurately reproduces APT scenarios using real systems and executes a wide range of authentic Intrusion Response System (IRS) actions. This setup includes time and variability constraints commonly encountered in operational environments, offering a more practical alternative to traditional simulations. The RL agents, implemented using Proximal Policy Optimization (PPO) and Deep Q-Network (DQN) algorithms, were both trained and evaluated within this industrial-style emulated environment. Empirical results demonstrate that both DRL algorithms successfully learned effective and well-timed defensive actions under realistic constraints, confirming their capability to operate in dynamic, real-world APT scenarios. Eider Iturbe, Angel Rego, Oscar Llorente-Vazquez, Erkuden Rios, Christos Dalamagkas, Dimitris Merkouris, Nerea Toledo |
Expert Syst. Appl. | 7 |
| 2026 | A pattern-aware LSTM-based approach for APT detection leveraging a realistic dataset for critical infrastructure securityabstractAdvanced Persistent Threats (APTs) represent some of the most sophisticated and coordinated cyberattacks, often targeting critical infrastructure with stealthy, multi-stage techniques. Despite the availability of numerous intrusion detection datasets, most fail to capture the sequential and strategic nature of APT campaigns as outlined in frameworks like MITRE ATT&CK. This paper introduces a novel dataset based on a realistic emulation of the Sandworm APT group targeting the Supervisory Control and Data Acquisition (SCADA) system of a Wide Area Measurement System (WAMS). The dataset captures the full lifecycle of an APT attack, from initial access to impact, in a structured and time-ordered manner, enabling the study of both atomic and multi-step intrusion behaviours. We train and evaluate supervised multiclass sequence-aware models, specifically Long Short-Term Memory (LSTM) and Bidirectional LSTM (BiLSTM) architectures, to detect these behaviours using network flow data, assessing their performance and analysing their strengths and limitations. Our results show that BiLSTM models offer greater stability and generalization, while LSTM models achieve competitive performance with optimal configurations. These findings highlight the importance of realistic, sequence-aware datasets for developing robust intrusion detection systems tailored to modern APT threats. Eider Iturbe, Christos Dalamagkas, Panagiotis I. Radoglou-Grammatikis, Erkuden Rios, Nerea Toledo |
Future Gener. Comput. Syst. | 5 |
| 2024 | A Multi-layer Approach through Threat Modelling and Attack Simulation for Enhanced Cyber Security AssessmentabstractThere is a growing concern about the dynamic landscape of cyber security threats escalating, and the need for improvement in defence capabilities against emerging sophisticated incidents. In response, this paper presents a solution called the Cyber Incident Simulation System, which enables system security engineers to simulate cyber-physical attacks and incidents without the requirement to affect or disrupt the ongoing business operation of the system. Leveraging graph-based threat modelling and AI-generated incident data, the system empowers professionals to predict the effect of the incident within the system under study. The synthetic data is used by anomaly-based Intrusion Detection Systems (IDSs) and other additional security controls to improve their detection algorithms to enhance their accuracy and effectiveness. The Cyber Incident Simulation System is designed to enhance the cyber security measures through the simulation of various incident scenarios. Eider Iturbe, Javier Arcas, Erkuden Rios, Nerea Toledo |
ARES | 4 |
| 2024 | Unleashing offensive artificial intelligence: Automated attack technique code generationabstractArtificial Intelligence (AI) technology is revolutionizing the digital world and becoming the cornerstone of the modern digital systems. The capabilities of cybercriminals are expanding as they adopt new technologies like zero-day exploits or new business models such as hacker-as-a-service. While AI capabilities can improve cybersecurity measures, this same technology can also be utilized as an offensive cyber weapon to create sophisticated and intricate cyber-attacks. This paper describes an AI-powered mechanism for the automatic generation of attack techniques, ranging from initial attack vectors to impact-related actions. It presents a comprehensive analysis of simulated attacks by highlighting the attack tactics and techniques that are more likely to be generated using AI technology, specifically Large Language Model (LLM) technology. The work empirically demonstrates that LLM technology can be easily used by cybercriminals for attack execution. Moreover, the solution can complement Breach and Attack Simulation (BAS) platforms and frameworks that automate the security assessment in a controlled manner. BAS could be enhanced with AI-powered attack simulation by bringing forth new ways to automatically program multiple attack techniques, even multiple versions of the same attack technique. Therefore, AI-enhanced attack simulation can assist in ensuring digital systems are bulletproof and protected against a great variety of attack vectors and actions. Eider Iturbe, Oscar Llorente-Vazquez, Angel Rego, Erkuden Rios, Nerea Toledo |
Comput. Secur. | 5 |
| 2023 | Artificial Intelligence for next generation cybersecurity: The AI4CYBER frameworkabstractArtificial Intelligence (AI) is playing a crucial role both in the technological advances and emerging advanced threats in cybersecurity. Despite efforts by competent authorities in Europe to regulate the use of AI in a way that aligns with the ethics and individuals’ fundamental rights, there are still challenges to be tackled, not to mention the malicious use of AI by cybercriminals. In this paper we present a novel framework that is composed of innovative cybersecurity services that leverage AI to provide support in the management of the incident response and recovery lifecycle of the critical entities’ systems against advanced attacks. The paper describes the main components and architecture of the AI4CYBER framework and provides a clear understanding of the application of the autonomous intelligent cybersecurity services and their role in enforcing defensive actions throughout the entire lifecycle of the systems. Eider Iturbe, Erkuden Rios, Angel Rego, Nerea Toledo |
ARES | 4 |
| 2023 | Towards trustworthy Artificial Intelligence: Security risk assessment methodology for Artificial Intelligence systemsabstractThe digitalization and smartization of modern digital systems include the implementation and integration of emerging innovative technologies, such as Artificial Intelligence. By incorporating new technologies, the surface attack of the system also expands, and specialized cybersecurity mechanisms and tools are required to counter the potential new threats. This paper introduces a holistic security risk assessment methodology that aims to assist Artificial Intelligence system stakeholders guarantee the correct design and implementation of technical robustness in Artificial Intelligence systems. The methodology is designed to facilitate the automation of the security risk assessment of Artificial Intelligence components together with the rest of the system components. Supporting the methodology, the solution to the automation of Artificial Intelligence risk assessment is also proposed. Both the methodology and the tool will be validated when assessing and treating risks on Artificial Intelligence-based cybersecurity solutions integrated in modern digital industrial systems that leverage emerging technologies such as cloud continuum including Software-defined networking (SDN). Eider Iturbe, Erkuden Rios, Nerea Toledo |
CloudCom | 3 |
| 2020 | Guidelines for Simulating/Emulating Software-Defined Networks in Connected VehiclesabstractIn the vehicular scenario, on-site testing is particularly complex, time-consuming and expensive. A reduction of such testing can be achieved by improving the efficiency of the laboratory tests. For that purpose, making the right choice of the Simulation/Emulation (S/E) framework for each activity is crucial. However, the availability of specific S/E tools to model Software-Defined Networks (SDNs) in the context of vehicular networks is limited. Researchers and practitioners face the challenge of dedicating too much time to identify and master complex tools and frameworks with huge learning curves. In this paper, we propose a methodology to guide professionals in the identification of the most suitable S/E tool depending on a set of features related to SDN and the most relevant requirements for the vehicular context. For that purpose, a ranked functional comparison of current available S/E tools is performed. David Franco, Marina Aguado, Nerea Toledo, Maria Victoria Higuero |
VTC Spring | 3 |
| 2018 | A Framework for Vulnerability Detection in European Train Control Railway CommunicationsabstractRailway systems have evolved considerably in the last years with the adoption of new communication technologies. Aiming to achieve a single European railway network, the European Rail Traffic Management System (ERTMS) emerged in Europe to substitute multiple and noninteroperable national railway communication systems. This system and its security strategies were designed in late 1990s. Recent works have identified vulnerabilities related to integrity, authenticity, availability, and confidentiality. In the context of defining effective countermeasures to mitigate potential vulnerabilities, these vulnerabilities have to be analysed. In this article we introduce a framework that attempts to challenge ERTMS security by evaluating the exploitability of these vulnerabilities. Irene Arsuaga, Nerea Toledo, Igor Lopez, Marina Aguado |
Secur. Commun. Networks | 2 |
| 2016 | An architecture for dynamic QoS management at Layer 2 for DOCSIS access networks using OpenFlow
Alaitz Mendiola, Victor Fuentes, Jon Matías, Jasone Astorga, Nerea Toledo, Eduardo Jacob, Maider Huarte |
Comput. Networks | 5 |
| 2015 | A lossy channel aware parameterisation of a novel security protocol for wireless IP-enabled sensors
Jasone Astorga, Eduardo Jacob, Nerea Toledo, Marina Aguado, Maria Victoria Higuero |
Wirel. Networks | 3 |
| 2014 | Enhancing secure access to sensor data with user privacy support
Jasone Astorga, Eduardo Jacob, Nerea Toledo, Juanjo Unzilla |
Comput. Networks | 3 |
| 2014 | The EHU-OEF: An OpenFlow-based Layer-2 experimental facility
Jon Matías, Alaitz Mendiola, Nerea Toledo, Borja Tornero, Eduardo Jacob |
Comput. Networks | 3 |
| 2013 | Design and formal security evaluation of NeMHIP: A new secure and efficient network mobility management protocol based on the Host Identity Protocol
Nerea Toledo, Maria Victoria Higuero, Jasone Astorga, Marina Aguado, Jean-Marie Bonnin |
Comput. Secur. | 1 |
| 2013 | A high performance link layer mobility management strategy for professional private broadband networks
Jasone Astorga, Marina Aguado, Nerea Toledo, Maria Victoria Higuero |
J. Netw. Comput. Appl. | 3 |
| 2013 | Performance evaluation of user applications in the ITS scenario: An analytical assessment of the NeMHIP
Nerea Toledo, Jean-Marie Bonnin, Maria Victoria Higuero |
J. Netw. Comput. Appl. | 1 |
| 2011 | Fundamentals of NeMHIP: An enhanced HIP based NEMO protocolabstractThe provision of NEMO support based on an end-to-end protocol presents manageability challenges that are usually overcome delegating the signaling rights to the MR. In addition, whether the protocol is focused on establishing security associations, how these are rekeyed through a proxy-based process with no security threats should be solved. In this work we focus on the HIP protocol and analyze existing HIP based NEMO solutions. Based on found limitations, we outline the fundamentals of our protocol, NeMHIP. Nerea Toledo, Jean-Marie Bonnin, Maria Victoria Higuero, Eduardo Jacob |
CCNC | 1 |
| 2011 | Host Identity Protocol Based NEMO Solutions: An Evaluation of the Signaling OverheadabstractWith the goal of solving shortcomings of MIPv6, alternative protocols such as HIP have been proposed by the research community. In the same way as for MIPv6, solutions to cover NEMO scenarios based on HIP have been worked out. However, there is little agreement on which the best way is to handle NEMO scenarios when using HIP. In this work we analyze different HIP based NEMO solutions and define mathematical models for their analysis. These models are utilized for evaluating the signaling overhead of HIP based NEMO protocols in order to provide insight in the specification of the features a HIP based NEMO solution should fulfill. Nerea Toledo, Jean-Marie Bonnin, Maria Victoria Higuero, Eduardo Jacob |
VTC Spring | 1 |