VLDB 2026 Research / reviewers in the wild / expert
Alvaro A. Cárdenas
dblp:48/6119 · also Alvaro A. Cárdenas-Mora
· DBLP profile ↗
51ranked-venue papers
11as first author
14since 2021 · last 2026
0000-0002-5142-9750ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 6 first-author · 10 since 2021Computer networks · 6 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 6Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorSystems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: A Defense-Oriented Evaluation of Software Supply Chain Security
Eman Abu Ishgair, Juanita Gomez, Marcela S. Melara, Alvaro A. Cárdenas, Santiago Torres-Arias |
EuroS&P | 4 |
| 2025 | A Systematic Evaluation of Generative Models on Tabular Transportation Data
Chengen Wang 0001, Alvaro A. Cárdenas, Gurcan Comert, Murat Kantarcioglu |
PAKDD (7) | 2 |
| 2024 | From Power to Water: Dissecting SCADA Networks Across Different Critical Infrastructures
Neil Ortiz Silva, Martin Rosso, Emmanuele Zambon, Jerry den Hartog, Alvaro A. Cárdenas |
PAM (1) | 5 |
| 2024 | Fast Attack Recovery for Stochastic Cyber-Physical SystemsabstractCyber-physical systems tightly integrate computational resources with physical processes through sensing and actuating, widely penetrating various safety-critical domains, such as autonomous driving, medical monitoring, and industrial control. Unfortunately, they are susceptible to assorted attacks that can result in injuries or physical damage soon after the system is compromised. Consequently, we require mechanisms that swiftly recover their physical states, redirecting a compromised system to desired states to mitigate hazardous situations that can result from attacks. However, existing recovery studies have overlooked stochastic uncertainties that can be unbounded, making a recovery infeasible or invalidating safety and real-time guarantees. This paper presents a novel recovery approach that achieves the highest probability of steering the physical states of systems with stochastic uncertainties to a target set rapidly or within a given time. Further, we prove that our method is sound, complete, fast, and has low computational complexity if the target set can be expressed as a strip. Finally, we demonstrate the practicality of our solution through the implementation in multiple use cases encompassing both linear and nonlinear dynamics, including robotic vehicles, drones, and vehicles in high-fidelity simulators. Lin Zhang 0039, Luis Burbano, Xin Chen 0002, Alvaro A. Cárdenas, Steven Drager 0001, Fanxin Kong |
RTAS | 4 |
| 2024 | A Tale of Two Industroyers: It was the Season of DarknessabstractIn this paper, we study two pieces of malware that attempted to create blackouts in Ukraine. In particular, we design and develop a new sandbox that emulates different networks, devices, and other characteristics so that we can execute malware targeting substation equipment and understand in detail the specific sequence of actions the attackers could perform on substation equipment. We also study the effects that future similar malware can have. Our findings include new malware behavior not previously documented (such as the detailed algorithm for the MMS protocol payload) and an illustration of how attacking different targets will produce different effects. Luis E. Salazar, Sebastián R. Castro, Juan Lozano, Keerthi Koneru, Emmanuele Zambon, Ross Baldick, Marina Krotofil, Alonso Rojas, Alvaro A. Cárdenas |
SP | 10 |
| 2024 | SoK: Security of Programmable Logic Controllers
Efrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi 0002, Alvaro A. Cárdenas |
USENIX Security Symposium | 5 |
| 2023 | Provable Adversarial Safety in Cyber-Physical SystemsabstractMost proposals for securing control systems are heuristic in nature, and while they increase the protection of their target, the security guarantees they provide are unclear. This paper proposes a new way of modeling the security guarantees of a Cyber-Physical System (CPS) against arbitrary false command attacks. As our main case study, we use the most popular testbed for control systems security. We first propose a detailed formal model of this testbed and then show how the original configuration is vulnerable to a single-actuator attack. We then propose modifications to the control system and prove that our modified system is secure against arbitrary, single-actuator attacks. John H. Castellanos, Mohamed Maghenem, Alvaro A. Cárdenas, Ricardo G. Sanfelice, Jianying Zhou 0001 |
EuroS&P | 3 |
| 2023 | Resilient Structural Sparsity in the Design of Consensus NetworksabstractThe consensus problem is relevant to different areas ranging from biology, social psychology, and physics to power systems and robotics. Two crucial aspects of the design of a consensus system are the implementation issues that arise in densely connected networks and the presence of malicious agents that try to cause a deviation from a synchronization state. In this article, we introduce a formulation to design the topology of a consensus network to improve its resilience to attacks while remaining sparse and consistent with the a priori structural relations between the agents. Through mathematical analysis and simulations on artificial and real-world cases, we show the benefits and usefulness of using this strategy to design resilient and structurally sparse consensus networks. Gilberto Díaz-García, Gabriel Narváez, Luis Felipe Giraldo, Jairo Alonso Giraldo, Alvaro A. Cárdenas |
IEEE Trans. Cybern. | 5 |
| 2022 | CPSS '22: 8th ACM Cyber-Physical System Security WorkshopabstractCyber-Physical Systems (CPS) consist of large-scale interconnected systems of heterogeneous components interacting with their physical environments. There exist a multitude of CPS devices and applications deployed to serve critical functions in our lives thus making security an important non-functional attribute of such systems. CPSS'22 workshop will provide a platform for professionals from academia, government, and industry to discuss novel ways to address the ever-present security and privacy challenges in CPS. Alvaro A. Cárdenas, Daisuke Mashima |
AsiaCCS | 1 |
| 2022 | MaDIoT 2.0: Modern High-Wattage IoT Botnet Attacks and Defenses
Tohid Shekari, Alvaro A. Cárdenas, Raheem A. Beyah |
USENIX Security Symposium | 2 |
| 2022 | A fast and accurate threat detection and prevention architecture using stream processingabstractSummary Late detection of security breaches increases the risk of irreparable damages and limits any mitigation attempts. We propose a fast and accurate threat detection and prevention architecture that combines the advantages of real‐time streaming with batch processing over a historical database. We create a dataset by capturing both legitimate and malicious traffic and propose two ways of combining packets into flows, one considering a time window and the other analyzing the first few packets of each flow per period. We also investigate the effectiveness of our proposal on real‐world network traces obtained from a significant Brazilian network operator providing broadband Internet to their customers. We implement and evaluate three classification algorithms and two anomaly detection methods. The results show an accuracy higher than 95% and an excellent trade‐off between attack detection and false‐positive rates. We further propose an improved scheme based on software defined networks that automatically prevents threats by analyzing only the first few packets of a flow. The proposal promptly and efficiently blocks threats, is robust, and can scale up, even when the attacker employs spoofed IP. Antonio G. P. Lobato, Martin Andreoni, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle |
Concurr. Comput. Pract. Exp. | 3 |
| 2021 | MaMIoT: Manipulation of Energy Market Leveraging High Wattage IoT BotnetsabstractIf a trader could predict price changes in the stock market better than other traders, she would make a fortune. Similarly in the electricity market, a trader that could predict changes in the electricity load, and thus electricity prices, would be able to make large profits. Predicting price changes in the electricity market better than other market participants is hard, but in this paper, we show that attackers can manipulate the electricity prices in small but predictable ways, giving them a competitive advantage in the market. Tohid Shekari, Celine Irvene, Alvaro A. Cárdenas, Raheem A. Beyah |
CCS | 3 |
| 2021 | You Make Me Tremble: A First Look at Attacks Against Structural Control SystemsabstractThis paper takes a first look at the potential consequences of cyberattacks against structural control systems. We design algorithms and implement them in a testbed and on well-known benchmark models for buildings and bridges. Our results show that attacks to structures equipped with semi-active and active vibration control systems can let the attacker oscillate the building or bridge at the resonance frequency, effectively generating threats to the structure and the people using it. We also implement and test the effectiveness of attack-detection systems. Abel Zambrano, Alejandro Palacio Betancur, Luis Burbano, Andres Felipe Niño, Luis Felipe Giraldo, Mariantonieta Gutierrez Soto, Jairo Alonso Giraldo, Alvaro A. Cárdenas |
CCS | 8 |
| 2021 | AttkFinder: Discovering Attack Vectors in PLC Programs using Information Flow AnalysisabstractTo protect an Industrial Control System (ICS), defenders need to identify potential attacks on the system and then design mechanisms to prevent them. Unfortunately, identifying potential attack conditions is a time-consuming and error-prone process. In this work, we propose and evaluate a set of tools to symbolically analyse the software of Programmable Logic Controllers (PLCs) guided by an information flow analysis that takes into account PLC network communication (compositions). Our tools systematically analyse malicious network packets that may force the PLC to send specific control commands to actuators. We evaluate our approach in a real-world system controlling the dosing of chemicals for water treatment. Our tools are able to find 75 attack tactics (56 were novel attacks), and we confirm that 96% of these tactics cause the intended effect in our testbed. John H. Castellanos, Martín Ochoa, Alvaro A. Cárdenas, Owen Arden, Jianying Zhou 0001 |
RAID | 3 |
| 2020 | DARIA: Designing Actuators to Resist Arbitrary Attacks Against Cyber-Physical SystemsabstractIn the past decade we have seen an active research community proposing attacks and defenses to Cyber-Physical Systems (CPS). Most of these attacks and defenses have been heuristic in nature, limiting the attacker to a set of predefined operations, and proposing defenses with unclear security guarantees. In this paper, we propose a generic adversary model that can capture any type of attack (our attacker is not constrained to follow specific attacks such as replay, delay, or bias) and use it to design security mechanisms with provable security guarantees. In particular, we propose a new secure design paradigm we call DARIA: Designing Actuators to Resist arbItrary Attacks. The main idea behind DARIA is the design of physical limits to actuators in order to prevent attackers from arbitrarily manipulating the system, irrespective of their point of attack (sensors or actuators) or the specific attack algorithm (bias, replay, delays, etc.). As far as we are aware, we are the first research team to propose the design of physical limits to actuators in a control loop in order to keep the system secure against attacks. We demonstrate the generality of our proposal on simulations of vehicular platooning and industrial processes. Jairo Alonso Giraldo, Sahand Hadizadeh Kafash, Justin Ruths, Alvaro A. Cárdenas |
EuroS&P | 4 |
| 2020 | Uncharted Networks: A First Measurement Study of the Bulk Power SystemabstractIn the last two decades, the communication technologies used for supervision and control of critical infrastructures such as the power grid, have been migrating from serial links to Internet-compatible network protocols. Despite this trend, the research community has not explored or measured the unique characteristics of these industrial systems, and as a result, most of these networks remain unstudied. In this paper we perform the first measurement study of a Supervisory Control And Data Acquisition (SCADA) network in the bulk power grid. We develop a new protocol parser that can be used to analyze packets not conforming to standards, find attributes to profile the SCADA network, and identify several outliers which underscore the difficulties in managing a federated network where different devices are under the control of different power companies. Kelvin Mai, Neil Ortiz Silva, Jason Molina, Alvaro A. Cárdenas |
Internet Measurement Conference | 5 |
| 2020 | Adversarial Classification Under Differential Privacy
Jairo Alonso Giraldo, Alvaro A. Cárdenas, Murat Kantarcioglu, Jonathan Katz |
NDSS | 2 |
| 2020 | Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear ApproximationsabstractAttack detection and recovery are fundamental elements for the operation of safe and resilient cyber-physical systems. Most of the literature focuses on attack-detection, while leaving attack-recovery as an open problem. In this paper, we propose novel attack-recovery control for securing cyber-physical systems. Our recovery control consists of new concepts required for a safe response to attacks, which includes the removal of poisoned data, the estimation of the current state, a prediction of the reachable states, and the online design of a new controller to recover the system. The synthesis of such recovery controllers for cyber-physical systems has barely investigated so far. To fill this void, we present a formal method-based approach to online compute a recovery control sequence that steers a system under an ongoing sensor attack from the current state to a target state such that no unsafe state is reachable on the way. The method solves a reach-avoid problem on a Linear Time-Invariant (LTI) model with the consideration of an error bound ε ≥ 0. The obtained recovery control is guaranteed to work on the original system if the behavioral difference between the LTI model and the system's plant dynamics is not larger than ε. Since a recovery control should be obtained and applied at the runtime of the system, in order to keep its computational time cost as low as possible, our approach firstly builds a linear programming restriction with the accordingly constrained safety and target specifications for the given reach-avoid problem, and then uses a linear programming solver to find a solution. To demonstrate the effectiveness of our method, we provide (a) the comparison to the previous work over 5 system models under 3 sensor attack scenarios: modification, delay, and reply; (b) a scalability analysis based on a scalable model to evaluate the performance of our method on large-scale systems. Lin Zhang 0039, Xin Chen 0002, Fanxin Kong, Alvaro A. Cárdenas |
RTSS | 4 |
| 2020 | SAVIOR: Securing Autonomous Vehicles with Robust Physical Invariants
Raul Quinonez, Jairo Alonso Giraldo, Luis E. Salazar, Erick Bauman, Alvaro A. Cárdenas, Zhiqiang Lin 0001 |
USENIX Security Symposium | 5 |
| 2020 | Introduction to the Special Issue on User-Centric Security and Safety for CPSabstractNo abstract available. Neetesh Saxena, Alvaro A. Cárdenas, Raheem A. Beyah, Rongxing Lu, Kim-Kwang Raymond Choo, Yiran Chen 0001 |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2020 | Guest Editorial: Special Section on Security and Privacy in Industry 4.0abstractThe papers in this special section focuses on security and privacy in industry. Industries, governments, and scientific communities are increasingly drawing special attention to competitive advantages that Industry 4.0 can bring to business sustainability and economy of a country. The tendency to couple information technologies (ITs) with the existing operational technologies (OTs) adds new opportunities to improve and optimize operational processes, products, and services in which multiple stakeholders (e.g., end-users) can interact with the new industrial ecosystems to speed up and customize processes. In this sense, Industry 4.0 constitutes a relevant investment source composed of a complex technological showcase in which multiple connections and accesses can arise, seriously impacting on the good performance of the different production and distribution chains associated with smart factories and manufacturing, smart grid systems, smart transportation, or smart health environments. Cristina Alcaraz, Yan Zhang 0002, Alvaro A. Cárdenas, Liehuang Zhu |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | Hide and Seek: An Architecture for Improving Attack-Visibility in Industrial Control Systems
Jairo Alonso Giraldo, David I. Urbina, Alvaro A. Cárdenas, Nils Ole Tippenhauer |
ACNS | 3 |
| 2019 | Not Everything is Dark and Gloomy: Power Grid Protections Against IoT Demand Attacks
Alvaro A. Cárdenas, Ross Baldick |
USENIX Security Symposium | 2 |
| 2019 | Improving the Security of Visual ChallengesabstractThis article proposes new tools to detect the tampering of video feeds from surveillance cameras. Our proposal illustrates the unique cyber-physical properties that sensor devices can leverage for their cyber-security. While traditional attestation algorithms exchange digital challenges between devices authenticating each other, our work instead proposes challenges that manifest physically in the field of view of the camera (e.g., a QR code in a display). This physical (challenge) and cyber (verification) attestation mechanism can help protect systems even when the sensors (cameras) and actuators (a display, infrared LEDs, color light bulbs) are compromised. In this article, we consider skillful adversaries that can capture the correct challenges (our system is sending) and can re-create them in the response to try fooling our verification system, and we propose new algorithms to detect these powerful attackers. Also, we introduce new visual challenges that make harder for anti-forensics attackers to succeed, and we present experimental results showing how our system is robust against a variety of attacks ranging from naive attacks to more sophisticated anti-forensics attackers. Junia Valente, Kanchan Bahirat, Kelly Venechanos, Alvaro A. Cárdenas, B. Prabhakaran 0001 |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2019 | Impact of the Market Infrastructure on the Security of Smart GridsabstractWe study the resiliency of demand response (DR) systems to data integrity attacks. In particular, we compare two popular proposals for DR: 1) a centralized direct load control system, and 2) a decentralized dynamic prices system. Through an economic analysis, we show that decentralized dynamic pricing systems are more resilient to attacks that try to defraud (or damage) the system. On the other hand, we show that this resiliency comes with a disadvantage for detecting attacks, as distinguishing attacks from system failures is harder in systems with dynamic prices. We also propose penalties for the users who benefit from an attack. The penalties depend on the estimated losses of victims and can discourage rational attackers from launching attacks in the first place. Carlos A. Barreto, Alvaro A. Cárdenas |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | An Adaptive Real-Time Architecture for Zero-Day Threat DetectionabstractAttackers create new threats and constantly change their behavior to mislead security systems. In this paper, we propose an adaptive threat detection architecture that trains its detection models in real time. The major contributions of the proposed architecture are: i) gather data about zero-day attacks and attacker behavior using honeypots in the network; ii) process data in real time and achieve high processing throughput through detection schemes implemented with stream processing technology; iii) use of two real datasets to evaluate our detection schemes, the first from a major network operator in Brazil and the other created in our lab; iv) design and development of adaptive detection schemes including both online trained supervised classification schemes that update their parameters in real time and learn zero-day threats from the honeypots, and online trained unsupervised anomaly detection schemes that model legitimate user behavior and adapt to changes. The performance evaluation results show that proposed architecture maintains an excellent trade-off between threat detection and false positive rates and achieves high classification accuracy of more than 90%, even with legitimate behavior changes and zero-day threats. Antonio G. P. Lobato, Martin Andreoni, Igor Jochem Sanz, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle |
ICC | 4 |
| 2018 | ALERT: Adding a Secure Layer in Decision Support for Advanced Driver Assistance System (ADAS)abstractWith the ever-increasing popularity of LiDAR (Light Image Detection and Ranging) sensors, a wide range of applications such as vehicle automation and robot navigation are developed utilizing the 3D LiDAR data. Many of these applications involve remote guidance - either for safety or for the task performance - of these vehicles and robots. Research studies have exposed vulnerabilities of using LiDAR data by considering different security attack scenarios. Considering the security risks associated with the improper behavior of these applications, it has become crucial to authenticate the 3D LiDAR data that highly influence the decision making in such applications. In this paper, we propose a framework, ALERT (Authentication, Localization, and Estimation of Risks and Threats), as a secure layer in the decision support system used in the navigation control of vehicles and robots. To start with, ALERT tamper-proofs 3D LiDAR data by employing an innovative mechanism for creating and extracting a dynamic watermark. Next, when tampering is detected (because of the inability to verify the dynamic watermark), ALERT then carries out cross-modal authentication for localizing the tampered region. Finally, ALERT estimates the level of risk and threat based on the temporal and spatial nature of the attacks on LiDAR data. This estimation of risk and threats can then be incorporated into the decision support system used by ADAS (Advanced Driver Assistance System). We carried out several experiments to evaluate the efficacy of the proposed ALERT for ADAS and the experimental results demonstrate the effectiveness of the proposed approach. Kanchan Bahirat, Umang Shah, Alvaro A. Cárdenas, B. Prabhakaran 0001 |
ACM Multimedia | 3 |
| 2018 | Virtual incident response functions in control systems
Andrés Felipe Murillo-Piedrahita, Vikram Gaur, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Sandra Julieta Rueda |
Comput. Networks | 4 |
| 2018 | Quantifying the Utility-Privacy Tradeoff in the Internet of ThingsabstractThe Internet of Things (IoT) promises many advantages in the control and monitoring of physical systems from both efficacy and efficiency perspectives. However, in the wrong hands, the data might pose a privacy threat. In this article, we consider the tradeoff between the operational value of data collected in the IoT and the privacy of consumers. We present a general framework for quantifying this tradeoff in the IoT, and focus on a smart grid application for a proof of concept. In particular, we analyze the tradeoff between smart grid operations and how often data are collected by considering a realistic direct-load control example using thermostatically controlled loads, and we give simulation results to show how its performance degrades as the sampling frequency decreases. Additionally, we introduce a new privacy metric, which we call inferential privacy. This privacy metric assumes a strong adversary model and provides an upper bound on the adversary’s ability to infer a private parameter, independent of the algorithm he uses. Combining these two results allows us to directly consider the tradeoff between better operational performance and consumer privacy. Roy Dong, Lillian J. Ratliff, Alvaro A. Cárdenas, Henrik Ohlsson, S. Shankar Sastry |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2016 | Second Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC'16)abstractThe Second International Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC'16) is being held in conjunction with the 23rd ACM CCS Conference. This second edition follows a successful workshop held with ACM CCS in 2015. The workshop was motivated by several observations. First, cyber-physical systems represent the new frontier for cyber risk. The attack surface imposed by the convergence of computing, communications and physical control represents unique challenges for security researchers and practitioners. Second, majority of the published literature addressing the security and privacy of CPS reflect a field still in its infancy. As such, the overall principles, models, and theories for securing CPS have not yet emerged. Third, the organizers of this workshop strongly felt that a premiere forum associated with a premiere conference was needed for rapidly publishing diverse, multidisciplinary in-progress work on the security and privacy of CPS and galvanizing the research community. The set of accepted papers reflect this vision. We have organized an exciting program for this workshop and look forward to active participation in this and future workshops. Alvaro A. Cárdenas, Rakesh Bobba |
CCS | 1 |
| 2016 | Limiting the Impact of Stealthy Attacks on Industrial Control SystemsabstractWhile attacks on information systems have for most practical purposes binary outcomes (information was manipulated/eavesdropped, or not), attacks manipulating the sensor or control signals of Industrial Control Systems (ICS) can be tuned by the attacker to cause a continuous spectrum in damages. Attackers that want to remain undetected can attempt to hide their manipulation of the system by following closely the expected behavior of the system, while injecting just enough false information at each time step to achieve their goals. In this work, we study if attack-detection can limit the impact of such stealthy attacks. We start with a comprehensive review of related work on attack detection schemes in the security and control systems community. We then show that many of those works use detection schemes that are not limiting the impact of stealthy attacks. We propose a new metric to measure the impact of stealthy attacks and how they relate to our selection on an upper bound on false alarms. We finally show that the impact of such attacks can be mitigated in several cases by the proper combination and configuration of detection schemes. We demonstrate the effectiveness of our algorithms through simulations and experiments using real ICS testbeds and real ICS systems. David I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer, Junia Valente, Mustafa Amir Faisal, Justin Ruths, Richard Candell, Henrik Sandberg |
CCS | 3 |
| 2015 | Using Visual Challenges to Verify the Integrity of Security CamerasabstractWe propose a new way to verify the integrity and freshness of footage from security cameras by sending visual challenges to the area being monitored by the camera. We study the effectiveness of periodically updating plain text and QR code visual challenges, propose attack detection statistics for each of them, and study their performance under normal conditions (without attack) and against a variety of adversaries. Junia Valente, Alvaro A. Cárdenas |
ACSAC | 2 |
| 2015 | First Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC): Challenges and Research DirectionsabstractThe First International Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC) is being held in conjunction with the 22nd ACM CCS Conference. The workshop was motivated by several observations. First, cyber-physical systems represent the new frontier for cyber risk. The attack surface imposed by the convergence of computing, communications and physical control represents unique challenges for security researchers and practitioners. Second, majority of the published literature addressing the security and privacy of CPS reflect a field still in its infancy. As such, the overall principles, models, and theories for securing CPS have not yet emerged. Third, the organizers of this workshop strongly felt that a premiere forum associated with a premiere conference was needed for rapidly publishing diverse, multidisciplinary in-progress work on the security and privacy of CPS and galvanizing the research community. The set of accepted papers reflect this vision. Papers span cyber and control-theoretic foundations, intrusion detection, forensics management, vulnerability analysis and elimination, and field studies. We have organized an exciting program for this workshop and look forward to active participation in this and future workshops. Roshan K. Thomas, Alvaro A. Cárdenas, Rakesh Bobba |
CCS | 2 |
| 2014 | CPS: market analysis of attacks against demand response in the smart gridabstractDemand response systems assume an electricity retail-market with strategic electricity consuming agents. The goal in these systems is to design load shaping mechanisms to achieve efficiency of resources and customer satisfaction. Recent research efforts have studied the impact of integrity attacks in simplified versions of the demand response problem, where neither the load consuming agents nor the adversary are strategic. Carlos A. Barreto, Alvaro A. Cárdenas, Nicanor Quijano, Eduardo Mojica-Nava |
ACSAC | 2 |
| 2014 | CPS: driving cyber-physical systems to unsafe operating conditions by timing DoS attacks on sensor signalsabstractDoS attacks on sensor measurements used for industrial control can cause the controller of the process to use stale data. If the DoS attack is not timed properly, the use of stale data by the controller will have limited impact on the process; however, if the attacker is able to launch the DoS attack at the correct time, the use of stale data can cause the controller to drive the system to an unsafe state. Marina Krotofil, Alvaro A. Cárdenas, Bradley Manning, Jason Larsen |
ACSAC | 2 |
| 2014 | Cyber-Physical Systems AttestationabstractCyber-Physical Systems (CPS) are monitored and controlled by a wide variety of sensors and controllers. However, it has been repeatedly demonstrated that most of the devices interacting with the physical world (sensors and controllers) are extremely fragile to security incidents. One particular technology that can help us improve the trustworthiness of these devices is software attestation. While software attestation can help a verifier check the integrity of devices, it still has several drawbacks that have limited their application in the field, like establishing an authenticated channel, the inability to provide continuous attestation, and the need to modify devices to implement the attestation procedure. To overcome these limitations, we propose CPS-attestation as an attestation technique for control systems to attest their state to an external verifier. CPS-attestation enables a verifier to continuously monitor the dynamics of the control system over time and detect whether a component is not behaving as expected or if it is driving the system to an unsafe state. Our goal in this position paper is to initiate the discussion on the suitability of applying attestation techniques to control systems and the associated research challenges. Junia Valente, Carlos A. Barreto, Alvaro A. Cárdenas |
DCOSS | 3 |
| 2012 | Fifth ACM workshop on artificial intelligence and security (AISec 2012)abstractThe Workshop on Artificial Intelligence and Security (AISec) focuses on using Artificial Intelligence (AI) and Machine Learning methods to address the unique problems posed within the Security and Privacy application areas and on the implications of using those methods to solve such adversarial problems. The workshop serves as the premier venue for this particular fusion of application, algorithms, and theory and continues to attract submissions from a diverse set of researchers, who address newly arising problems within this ever growing field. The main goal of the workshop is to provide a forum for researchers within the Security, Privacy, Artificial Intelligence (AI), and Machine Learning communities to discuss the role of AI and learning in security and privacy applications and, conversely, to present the unique needs of these problems to the AI and learning communities. Alvaro A. Cárdenas, Blaine Nelson, Benjamin I. P. Rubinstein |
CCS | 1 |
| 2012 | Evaluating Electricity Theft Detectors in Smart Grid Networks
Daisuke Mashima, Alvaro A. Cárdenas |
RAID | 2 |
| 2011 | Attacks against process control systems: risk assessment, detection, and response
Alvaro A. Cárdenas, Saurabh Amin, Zong-Syun Lin, Yu-Lun Huang, Chi-Yen Huang, S. Shankar Sastry |
AsiaCCS | 1 |
| 2009 | Safe and Secure Networked Control Systems under Denial-of-Service Attacks
Saurabh Amin, Alvaro A. Cárdenas, S. Shankar Sastry |
HSCC | 2 |
| 2009 | Rethinking security properties, threat models, and the design space in sensor networks: A case study in SCADA systems
Alvaro A. Cárdenas, Tanya G. Roosta, S. Shankar Sastry |
Ad Hoc Networks | 1 |
| 2009 | Evaluation of detection algorithms for MAC layer misbehavior: theory and experiments
Alvaro A. Cárdenas, Svetlana Radosavac, John S. Baras |
IEEE/ACM Trans. Netw. | 1 |
| 2008 | Principled reasoning and practical applications of alert fusion in intrusion detection systemsabstractIt is generally believed that by combining several diverse intrusion detectors (i.e., forming an IDS ensemble), we may achieve better performance. However, there has been very little work on analyzing the effectiveness of an IDS ensemble. In this paper, we study the following problem: how to make a good fusion decision on the alerts from multiple detectors in order to improve the final performance. We propose a decision-theoretic alert fusion technique based on the likelihood ratio test (LRT). We report our experience from empirical studies, and formally analyze its practical interpretation based on ROC curve analysis. Through theoretical reasoning and experiments using multiple IDSs on several data sets, we show that our technique is more flexible and also outperforms other existing fusion techniques such as AND, OR, majority voting, and weighted voting. Guofei Gu, Alvaro A. Cárdenas, Wenke Lee |
AsiaCCS | 2 |
| 2008 | Research Challenges for the Security of Control Systems
Alvaro A. Cárdenas, Saurabh Amin, S. Shankar Sastry |
HotSec | 1 |
| 2007 | On Optimal Watermarking Schemes in Uncertain Gaussian ChannelsabstractThis paper describes the analytical derivation of a new watermarking algorithm satisfying optimality properties when the distortion of the watermarked signal is caused by a Gaussian process. We also extend previous work under the same assumptions and obtain more general solutions. Alvaro A. Cárdenas, George V. Moustakides, John S. Baras |
ICIP (4) | 1 |
| 2007 | Performance Comparison of Detection Schemes for MAC Layer MisbehaviorabstractThis paper revisits the problem of detecting greedy behavior in the IEEE 802.11 MAC protocol by evaluating the performance of two previously proposed schemes: DOMINO and the sequential probability ratio test (SPRT). The evaluation is carried out in four steps. We first derive a new analytical formulation of the SPRT that takes into account the discrete nature of the problem. Then we develop a new tractable analytical model for DOMINO. As a third step, we evaluate the theoretical performance of SPRT and DOMINO with newly introduced metrics that take into account the repeated nature of the tests. This theoretical comparison provides two major insights into the problem: it confirms the optimality of SPRT and motivates us to define yet another test, a nonparametric CUSUM statistic that shares the same intuition as DOMINO but gives better performance. We finalize the paper with experimental results, confirming our theoretical analysis and validating the introduction of the new nonparametric CUSUM statistic. Alvaro A. Cárdenas, Svetlana Radosavac, John S. Baras |
INFOCOM | 1 |
| 2007 | Optimal ROC Curve for a Combination of ClassifiersabstractWe present a new analysis for the combination of binary classifiers. We propose a theoretical framework based on the Neyman-Pearson lemma to analyze combinations of classifiers. In particular, we give a method for finding the optimal decision rule for a combination of classifiers and prove that it has the optimal ROC curve. We also show how our method generalizes and improves on previous work on combining classifiers and generating ROC curves. Marco Barreno, Alvaro A. Cárdenas, J. D. Tygar |
NIPS | 2 |
| 2007 | Detecting IEEE 802.11 MAC layer misbehavior in ad hoc networks: Robust strategies against individual and colluding attackersabstractSelfish behavior at the Medium Access (MAC) Layer can have devastating side effects on the performance of wireless networks, with effects similar to those of Denial of Service (DoS) attacks. In this paper we consider the problem of detection and prevention of node misbehavior at the MAC layer, focu sing on the back-off manipulation by selfish nodes. We first propose an algorithm that ensures honest behavior of non-colluding participants. Furthermore, we analyze the problem of colluding selfish nodes, casting the problem within a minimax robust detection framework and providing an optimal detection rule for the worst-case attack scenarios. Finally, we evaluate the performance of single and colluding attackers in terms of detection delay. Although our approach is general and can be used with any probabilistic distributed MAC protocol, we focus our analysis on the IEEE 802.11 MAC. Svetlana Radosavac, Alvaro A. Cárdenas, John S. Baras, George V. Moustakides |
J. Comput. Secur. | 2 |
| 2006 | B-ROC Curves for the Assessment of Classifiers over Imbalanced Data Sets
Alvaro A. Cárdenas, John S. Baras |
AAAI | 1 |
| 2006 | Towards a secure and interoperable DRM architectureabstractIn this paper we look at the problem of interoperability of digital rights management (DRM)systems in home networks. We introduce an intermediate module called the Domain Interoperability Manager (DIM) to efficiently deal with the problem of content and license translation across different DRM regimes. We also consider the threat model specific to interoperability systems, and introduce threats such as the cross-compliancy and splicing attacks. We formalize the adversary model and define security of an interoperable DRM system with respect to this adversary. We finalize by proposing detailed protocols which achieve our security requirements. In order to achieve these requirements we provide novel applications of recently proposed proxy resignature and proxy re-encryption algorithms. Gelareh Taban, Alvaro A. Cárdenas, Virgil D. Gligor |
Digital Rights Management Workshop | 2 |
| 2006 | A Framework for the Evaluation of Intrusion Detection SystemsabstractClassification accuracy in intrusion detection systems (IDSs) deals with such fundamental problems as how to compare two or more IDSs, how to evaluate the performance of an IDS, and how to determine the best configuration of the IDS. In an effort to analyze and solve these related problems, evaluation metrics such as the Bayesian detection rate, the expected cost, the sensitivity and the intrusion detection capability have been introduced. In this paper, we study the advantages and disadvantages of each of these performance metrics and analyze them in a unified framework. Additionally, we introduce the intrusion detection operating characteristic (IDOC) curves as a new IDS performance tradeoff which combines in an intuitive way the variables that are more relevant to the intrusion detection evaluation problem. We also introduce a formal framework for reasoning about the performance of an IDS and the proposed metrics against adaptive adversaries. We provide simulations and experimental results to illustrate the benefits of the proposed framework Alvaro A. Cárdenas, John S. Baras, Karl Seamon |
S&P | 1 |