VLDB 2026 Research / reviewers in the wild / expert
Antonio Pastor 0001
dblp:52/8149-1 · also Antonio Agustin Pastor Perales, Antonio Pastor Perales
· DBLP profile ↗
15ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0003-2849-9782ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Layered Secure and Post-Quantum Ready Communication Architecture for Microservice Platforms
Luis F. Gonzalez, Mattin Antartiko Elorza Forcada, Iván Vidal, Francisco Valera, Antonio Pastor 0001 |
NetSoft | 5 |
| 2026 | Quantum resistant software Defined-Networking IPsec, enabling ITS communication over IP networks on real telco infrastructuresabstract• The first functional implementation that integrates SDN, QKD, and IPsec technologies within a unified architecture, enabling dynamic establishment of IPsec tunnels protected with Quantum Key Distribution. • The proposed solution is based on the implementation of IPsec in accordance with QKD-related standards defined by ETSI, specifically adhering to the specifications ETSI GS QKD 004 and ETSI GS QKD 015. This approach ensures interoperability and alignment with current best practices for quantum secure network deployments. • Experimental results were obtained from a field-deployed QKD network operating over a hybrid quantum-classical infrastructure, providing empirical validation of the proposed approach in a production-grade environment laying a solid foundation for future large-scale deployments. The importance of digital communications makes protecting data in transit a critical priority. Internet Protocol Security (IPsec) plays a central role in this protection, by ensuring data confidentiality, integrity, and authenticity. However, quantum computing threatens the foundations of IPsec. Its ability to efficiently solve mathematical problems such as factoring and discrete logarithms could break the public-key cryptography used for IPsec key exchange. Quantum Key Distribution (QKD) is one of the most promising solutions to this problem, offering a security layer immune to both classical and quantum computational attacks. This work proposes a solution that integrates emerging quantum technologies into existing security and communication infrastructures to ensure long-term protection. We combine IPsec with Software-Defined Networking and QKD to build a novel network security infrastructure. It is designed to resist both classical and quantum threats. It is based on recent standardization efforts and operational tools for QKD integration. We demonstrate advanced capabilities such as rekeying and secure key transport on a field deployed QKD network operating within a shared quantum-classical production infrastructure. Rubén B. Mendez, Jaime S. Buruaga, Juan Pedro Brito, Antonio Pastor 0001, Diego R. López, Vicente Martín |
Comput. Networks | 4 |
| 2025 | CyberNEMO: Enhancing End-to-End Cybersecurity and Privacy in the IoT-Edge-Cloud ContinuumabstractAccording to the EU State of Cybersecurity report by the European Union Agency for Cybersecurity (ENISA), the number of cybersecurity-related incidents will increase by 24 percent by 2025, with ransomware and DoS/DDoS attacks being the most common. The emergence of new threats [1] and the consolidation of existing ones require doubling of efforts in proactive prevention and a decisive increase in research dedicated to cybersecurity. CyberNEMO (End-to-end Cybersecurity to NEMO meta-OS) project emerges as an evolution of the NEMO (Next Generation Meta Operating System) platform, designed to provide a secure, trustworthy, and robust execution environment across the IoT-Edge-Cloud computing continuum. Leveraging NEMO modular meta-operating system (mOS) framework, CyberNEMO introduces advanced cybersecurity and privacy-preserving mechanisms, emphasizing Zero Trust principles. This paper presents the CyberNEMO architecture, details its core innovative technologies, and describes its validation strategy through diverse living labs-including Smart Energy, Smart Water, Smart Manufacturing, Healthcare, Multimedia Distribution, and Smart Farming scenarios-demonstrating end-to-end cybersecurity and real-time threat mitigation capabilities, aligned with Europe's strategic cybersecurity goals. Theodore B. Zahariadis, Artemis C. Voulkidis, Ilias Nektarios Seitanidis, Andreas E. Papadakis, Alberto del Río, Javier Serrano 0003, David Jiménez, Antonio Pastor 0001, Diego R. López, Alejandro Muñiz, Mattin Antartiko Elorza Forcada, Ana Méndez, Wafa Ben Jaballah, Rosaria Rossini, Maria Belesioti, Ioannis P. Chochliouros, Marco Angelini, Vasileios Megalooikonomou, Carmela Occhipinti, Luigi Briguglio, Alexandru Plesa, Vladut Dinu, Mohammad Ghoreishi, Mostafa Jabari, Dimitrios Skias, Konstantinos Sakatis, Ioannis Papaefstathiou |
SRDS | 8 |
| 2024 | Framework for the development of a Network Digital TwinabstractNetwork Digital Twin (NDT) has emerged as a groundbreaking paradigm, revolutionizing the modeling of modern and complex networks. NDTs are emulation of real-world networks that can be used for a variety of purposes, such as network experimentation, optimization and security. NDTs achieve reproducibility by consistently producing results under identical conditions and repeatability by facilitating controlled variation experiments.The NDT proposed in this work is designed to be a versatile and adaptable platform, capable of supporting a wide range of network experimentation and optimization tasks, going beyond the limitations of existing solutions.This paper introduces our proposal for developing a NDT framework, providing insight into our ongoing work and the exploration, analysis, and conclusions we have reached in this context. In essence, this paper outlines our vision for a NDT in contrast to the NDT proposed in the literature. Ángela Burgaleta, Ignacio Dominguez Martinez-Casanueva, Amit Karamchandani, Diego R. López, Antonio Pastor 0001 |
NOMS | 5 |
| 2024 | Design of an AI-driven Network Digital Twin for advanced 5G-6G network managementabstractThe Network Digital Twin (NDT) developed in the B5GEMINI project is presented in this article, highlighting its architecture, objectives, functionalities, and practical applications. The design of the NDT architecture is detailed, including the establishment of the foundational infrastructure, developed as part of B5GEMINI-INFRA. The integration of artificial intelligence techniques for network management tasks within B5GEMINI-AIUC is illustrated with relevant use cases, such as the detection of cybersecurity attacks and the simulation and optimization of virtual reality applications, to demonstrate the usefulness and potential of the proposed NDT solution. The platform enables controlled experimentation and data collection for training Machine Learning (ML) models, addressing challenges associated with realistic network traffic datasets and cybersecurity experiments without disrupting live networks. The infrastructure supporting the NDT allows for creating virtual scenarios, isolating traffic between experiments, on-demand traffic generation, and capture, ensuring repeatability and enabling evaluation of different detection and mitigation tools under identical conditions. Additionally, an in-depth use case focusing on ML-based detection of a simulated denial of service attack through DNS over HTTPS within a 5G network framework showcases the NDT’s potential to provide a secure environment for testing and validating ML-based solutions without disrupting live networks. Amit Karamchandani, Mario Sanz Rodrigo, Ángela Burgaleta, Luis De La Cal, Alberto Mozo, José Ignacio Moreno, Antonio Pastor 0001, Diego R. López |
NOMS | 7 |
| 2024 | A methodological framework for optimizing the energy consumption of deep neural networks: a case study of a cyber threat detectorabstractAbstract The growing prevalence of deep neural networks (DNNs) across various fields raises concerns about their increasing energy consumption, especially in large data center applications. Identifying the best combination of optimization techniques to achieve maximum energy efficiency while maintaining system performance is challenging due to the vast number of techniques available, their complex interplay, and the rigorous evaluation required to assess their impact on the model. To address this gap, we propose an open-source methodological framework for the systematic study of the influence of various optimization techniques on diverse tasks and datasets. The goal is to automate experimentation, addressing common pitfalls and inefficiencies of trial and error, saving time, and allowing fair and reliable comparisons. The methodology includes model training, automatic application of optimizations, export of the model to a production-ready format, and pre- and post-optimization energy consumption and performance evaluation at inference time using various batch sizes. As a novelty, the framework provides pre-configured "optimization strategies" for combining state-of-the-art optimization techniques that can be systematically evaluated to determine the most effective strategy based on real-time energy consumption and performance feedback throughout the model life cycle. As an additional novelty, "optimization profiles" allow the selection of the optimal strategy for a specific application, considering user preferences regarding the trade-off between energy efficiency and performance. Validated through an empirical study on a DNN-based cyber threat detector, the framework demonstrates up to 82% reduction in energy consumption during inference with minimal accuracy loss. Amit Karamchandani, Alberto Mozo, Sandra Gómez Canaval, Antonio Pastor 0001 |
Neural Comput. Appl. | 4 |
| 2023 | A Multi-domain Testbed for Collaborative Research on the IoT-Edge-Cloud ContinuumabstractThis poster showcases an industry-academia collaboration between Telefónica and Universidad Carlos III de Madrid, aiming to establish a testbed to support research and experimentation with novel IoT, edge, and cloud computing technologies. The testbed has been deployed at the 5G Telefonica Open Network Innovation Centre (5TONIC), and enables the seamless integration of IoT/Edge/Cloud infrastructure domains using virtual and hardware components that can be made available both within 5TONIC and external premises. The design of the testbed is based on key enabling technologies in 5G/6G networking, including Network Function Virtualization (NFV), Software Defined Networking (SDN), and cloud-native computing, as well as on a Secure Infrastructure Abstraction (SIA) that facilitates automation and secure network communications. Iván Vidal, Luis F. Gonzalez, Francisco Valera, Borja Nogales, Raul Martin, Dulce N. de M. Artalejo, Diego R. López, Jose Manuel Manjón, Antonio Pastor 0001 |
SECON | 9 |
| 2023 | Using N-BEATS ensembles to predict automated guided vehicle deviationabstractAbstract A novel AGV (Automated Guided Vehicle) control architecture has recently been proposed where the AGV is controlled remotely by a virtual Programmable Logic Controller (PLC), which is deployed on a Multi-access Edge Computing (MEC) platform and connected to the AGV via a radio link in a 5G network. In this scenario, we leverage advanced deep learning techniques based on ensembles of N-BEATS (state-of-the-art in time-series forecasting) to build predictive models that can anticipate the deviation of the AGV’s trajectory even when network perturbations appear. Therefore, corrective maneuvers, such as stopping the AGV, can be performed in advance to avoid potentially harmful situations. The main contribution of this work is an innovative application of the N-BEATS architecture for AGV deviation prediction using sequence-to-sequence modeling. This novel approach allows for a flexible adaptation of the forecast horizon to the AGV operator’s current needs, without the need for model retraining or sacrificing performance. As a second contribution, we extend the N-BEATS architecture to incorporate relevant information from exogenous variables alongside endogenous variables. This joint consideration enables more accurate predictions and enhances the model’s overall performance. The proposed solution was thoroughly evaluated through realistic scenarios in a real factory environment with 5G connectivity and compared against main representatives of deep learning architectures (LSTM), machine learning techniques (Random Forest), and statistical methods (ARIMA) for time-series forecasting. We demonstrate that the deviation of AGVs can be effectively detected by using ensembles of our extended N-BEATS architecture that clearly outperform the other methods. Finally, a careful analysis of a real-time deployment of our solution was conducted, including retraining scenarios that could be triggered by the appearance of data drift problems. Amit Karamchandani, Alberto Mozo, Stanislav Vakaruk, Sandra Gómez Canaval, Jesús Enrique Sierra-García, Antonio Pastor 0001 |
Appl. Intell. | 6 |
| 2022 | Model-Driven Network Monitoring Using NetFlow Applied to Threat DetectionabstractIn recent years, several research works have proposed the analysis of network flow information using machine learning in order to detect threats or anomalous activities. In this sense, NetFlow-based systems stand out as one of the main sources of network flow information. In these systems, NetFlow collectors provide the flow monitoring information to be analyzed, but the particular information structure and format provided by different collector implementations is a recurring problem. In this paper, a new YANG data model is proposed as a standard model to use NetFlow-based monitoring data. In order to validate the proposal, a NetFlow collector incorporating the proposed NetFlow YANG model has been developed, to be integrated in a network scenario in which network flows are analyzed to detect malicious cryptomining activity. This collector extends an existing one, and provides design patterns to incorporate other existing collectors into this common data model. Our results show how, by using the YANG modeling language, network flow information can be handled and aggregated in a formal and unified way that provides flexibility and facilitates data analysis applied to threat detection. Daniel González-Sánchez, Ignacio Dominguez Martinez-Casanueva, Antonio Pastor 0001, Luis Bellido, Cristina Pinar Muñoz Zamarro, Alejandro Antonio Moreno Sancho, David Fernández 0002, Diego R. López |
NetSoft | 3 |
| 2022 | B5GEMINI: Digital Twin Network for 5G and BeyondabstractDigital Twin Network (DTN) is a new technology that builds on the concept of Digital Twins (DT) to create a virtual representation of the physical objects of a telecommunications network. DTN bridges physical and virtual spaces to enable coordination and synchronization of physical parts while eliminating the need to directly interact with them. In this work, we present B5GEMINI a DTN for 5G and beyond networks that makes an extensive use of artificial intelligence (AI). First, we present the infrastructural and architectural components that support B5GEMINI. Next, we explore five paradigmatic use cases where AI can leverage B5GEMINI for building new AI-powered applications. Finally, we identify the main components of the AI ecosystem of B5GEMINI. Alberto Mozo, Amit Karamchandani, Mario Sanz Rodrigo, José Ignacio Moreno, Antonio Pastor 0001 |
NOMS | 5 |
| 2022 | A Digital Twin for the 5G Era: the SPIDER Cyber RangeabstractService providers, 5G network operators and, more generally, vertical industries face today a dangerous shortage of highly skilled cybersecurity experts. Along with the escalation and growing sophistication of cyber-attacks, 5G networks require the training of skilled and highly competent cyber forces. To meet these requirements, the SPIDER cyber range focuses specifically on 5G, and is based on three pillars, (i) cyber security assessment, (ii) training cyber security teams to defend against complex cyber-attack scenarios, and (iii) evaluation of cyber risk. The SPIDER cyber range replicates a customized 5G network, enabling the execution of cyber-exercises that take advantage of hands-on interaction in real time, the sharing of information between participants, and the gathering of feedback from network equipment, as well as the development and adaptation of advanced operational procedures. This aims to help 5G security professionals improve their ability to collaboratively manage and predict security incidents, complex attacks, and propagated vulnerabilities. The SPIDER cyber range is validated in two relevant use case scenarios aimed at demonstrating, in a realistic, measurable, and replicable way the transformations SPIDER will bring to the cybersecurity industry. Filippo Rebecchi, Antonio Pastor 0001, Alberto Mozo, Chiara Lombardo, Roberto Bruschi, Ilias Aliferis, Roberto Doriguzzi Corin, Panagiotis Gouvas, Antonio Álvarez Romero, Anna Angelogianni, Ilias Politis, Christos Xenakis |
WoWMoM | 2 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 20 |
| 2019 | Adding Support for Automatic Enforcement of Security Policies in NFV NetworksabstractThis paper introduces an approach toward the automatic enforcement of security policies in network functions virtualization (NFV) networks and dynamic adaptation to network changes. The approach relies on a refinement model that allows the dynamic transformation of high-level security requirements into configuration settings for the network security functions (NSFs), and optimization models that allow the optimal selection of the NSFs to use. These models are built on a formalization of the NSF capabilities, which serves to unequivocally describe what NSFs are able to do for security policy enforcement purposes. The approach proposed is the first step toward a security policy aware NFV management, orchestration, and resource allocation system-a paradigm shift for the management of virtualized networks-and it requires minor changes to the current NFV architecture. We prove that our approach is feasible, as it has been implemented by extending the OpenMANO framework and validated on several network scenarios. Furthermore, we prove with performance tests that policy refinement scales well enough to support current and future virtualized networks. Cataldo Basile, Fulvio Valenza, Antonio Lioy, Diego R. López, Antonio Pastor 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2018 | The Mouseworld, a security traffic analysis lab based on NFV/SDNabstractMachine Learning (ML) technologies applied to Cybersecurity, especially in the area of network cyber threat detection, are a promising choice, but they require additional research in the applicability of a wide range of available algorithms. Such algorithms usually require training using good-quality and quantitatively significant datasets, which are rarely publicly available. To this end, in this paper we describe a novel experimental framework, that we call the Mouseworld, that combines NFV and SDN to create an environment able to (1) blend and transmit real and synthetic traffic and (2) collect and label this traffic in order to be utilised for training and validating ML algorithms that will be applied to the detection of cybersecurity threats. The Mouseworld framework includes a set of traffic generation, collection and labelling modules, jointly with analytics and algorithm training and visualization components. The OSM open-source network orchestrator is utilized to control and manage the framework and to deploy the training and validation scenarios. We present a preliminary result on the area of Security threat detection as a demonstration of the framework viability. Antonio Pastor 0001, Alberto Mozo, Diego R. López, Jesús Folgueira, Angeliki Kapodistria |
ARES | 1 |
| 2017 | SHIELD: A novel NFV-based cybersecurity frameworkabstractSHIELD is an EU-funded project, targeting at the design and development of a novel cybersecurity framework, which offers security-as-a-Service in an evolved telco environment. The SHIELD framework leverages NFV (Network Functions Virtualization) and SDN (Software-Defined Networking) for virtualization and dynamic placement of virtualised security appliances in the network (virtual Network Security Functions - vNSFs), Big Data analytics for real-time incident detection and mitigation, as well as attestation techniques for securing both the infrastructure and the services. This papers discusses key use cases and requirements for the SHIELD framework and presents a high-level architectural approach. Georgios Gardikis, K. Tzoulas, K. Tripolitis, A. Bartzas, Socrates Costicoglou, Antonio Lioy, Bernat Gastón, Carolina Fernandez 0001, Cristian Dávila, Antonis Litke, Antonio Pastor 0001, Jerónimo Núñez, Ludovic Jacquin, Hamza Attak, N. Davri, Georgios Xilouris, M. Kafetzakis, Dimitris Katsianis, Ioannis Neokosmidis, M. Terranova, C. Giustozzi, T. Batista, R. Preto, Eleni Trouva, Y. Angelopoulos, Akis Kourtis |
NetSoft | 13 |