VLDB 2026 Research / reviewers in the wild / expert
Carmen Fernández Gago
dblp:54/4845 · also M. Carmen Fernández Gago
· DBLP profile ↗
25ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0002-4564-6636ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 since 2021Computer networks · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial red teaming and imbalance correction in heterogeneous NIDS: A class-specific adaptive GAN frameworkabstractModern network infrastructures face a structural long-tail imbalance where malicious events are statistically negligible against benign traffic. This bias causes Machine Learning-based Network Intrusion Detection Systems (NIDS) to systematically overlook rare, high-severity intrusions. While Generative Adversarial Networks (GANs) offer a solution for minority class synthesis, standard monolithic architectures suffer from majority-class gradient dominance, inevitably leading to conditional mode collapse. To address this, we propose the Adaptive Manifold-Decoupled GAN (AMD-GAN), a novel framework that applies class-wise architectural decoupling to feature manifolds and dynamically adapts its optimization regime to each category’s cardinality. This decoupled design mitigates inter-class interference and empirically reduces critic memorization. Evaluated across three heterogeneous NIDS benchmarks (CIC-IDS2017, UNSW-NB15, Edge-IIoTset 2022), AMD-GAN achieves a mean global empirical Wasserstein distance of (across five independent seeds), confirming robust distributional fidelity. Under a Train-Synthetic-Test-Real (TSTR) protocol, balanced synthetic augmentation consistently improves Multiclass Macro F1-Scores. Specifically, in CIC-IDS2017, it yields a 10.1 pp absolute improvement (+45.2% Botnet, +22.9% Web Attack), demonstrating statistically significant superiority over interpolation methods like ADASYN and Borderline-SMOTE. An extensive ablation study isolates the adaptive engine as the causal driver of manifold recovery, while Distance to Closest Record (DCR) analysis confirms the absence of exact-match memorization. Furthermore, interpretability techniques (SHAP and LIME) validate that the generated flows preserve authentic protocol semantics, enabling unambiguous attribution for Security Operations Centers (SOC). Deployed offensively as an automated Red Teaming engine, AMD-GAN exposes structural fragility in operational tree ensembles, inducing up to 0.909 Macro F1-Score degradation under volumetric stress scenarios. Finally, the decoupled sequential training architecture restricts peak GPU VRAM to 1,575 MB while generating 90,000 synthetic flows in 15.7 s, establishing AMD-GAN as a computationally efficient, low-VRAM solution potentially suitable for resource-constrained deployments for robust data augmentation and adversarial NIDS auditing. Antonio Lara-Gutierrez, Carmen Fernández Gago, Jose Antonio Onieva |
J. Inf. Secur. Appl. | 2 |
| 2024 | A survey on IoT trust model frameworksabstractAbstract Trust can be considered as a multidisciplinary concept, which is strongly related to the context and it falls in different fields such as Philosophy, Psychology or Computer Science. Trust is fundamental in every relationship, because without it, an entity will not interact with other entities. This aspect is very important especially in the Internet of Things (IoT), where many entities produced by different vendors and created for different purposes have to interact among them through the internet often under uncertainty. Trust can overcome this uncertainty, creating a strong basis to ease the process of interaction among these entities. We believe that considering trust in the IoT is fundamental, and in order to implement it in any IoT entity, it is fundamental to consider it through the whole System Development Life Cycle. In this paper, we propose an analysis of different works that consider trust for the IoT. We will focus especially on the analysis of frameworks that have been developed in order to include trust in the IoT. We will make a classification of them providing a set of parameters that we believe are fundamental in order to properly consider trust in the IoT. Thus, we will identify important aspects to be taken into consideration when developing frameworks that implement trust in the IoT, finding gaps and proposing possible solutions. Davide Ferraris, Carmen Fernández Gago, Rodrigo Roman, Javier López 0001 |
J. Supercomput. | 2 |
| 2023 | A Test Environment for Wireless Hacking in Domestic IoT ScenariosabstractAbstract Security is gaining importance in the daily life of every citizen. The advent of Internet of Things devices in our lives is changing our conception of being connected through a single device to a multiple connection in which the centre of connection is becoming the devices themselves. This conveys the attack vector for a potential attacker is exponentially increased. This paper presents how the concatenation of several attacks on communication protocols (WiFi, Bluetooth LE, GPS, 433 Mhz and NFC) can lead to undesired situations in a domestic environment. A comprehensive analysis of the protocols with the identification of their weaknesses is provided. Some relevant aspects of the whole attacking procedure have been presented to provide some relevant tips and countermeasures. Antonio Muñoz 0001, Carmen Fernández Gago, Roberto López-Villa |
Mob. Networks Appl. | 2 |
| 2022 | Verification and Validation Methods for a Trust-by-Design Framework for the IoT
Davide Ferraris, Carmen Fernández Gago, Javier López 0001 |
DBSec | 2 |
| 2022 | Novel Approaches for the Development of Trusted IoT Entities
Davide Ferraris, Carmen Fernández Gago, Javier López 0001 |
SEC | 2 |
| 2021 | Stakeholder perspectives and requirements on cybersecurity in EuropeabstractThis article presents an overview and analysis of the key cybersecurity problems, challenges and requirements to be addressed in the future, which we derived through 63 interviews with European stakeholders from security-critical sectors including Open Banking, Supply Chain, Privacy-preserving Identity Management, Security Incident Reporting, Maritime Transport, Medical Data Exchange, and Smart Cities. We show that common problems, challenges and requirements across these sectors exist in relation to building trust, implementing privacy and identity management including secure and useable authentication, building resilient systems, standardisation and certification, achieving security and privacy by design, secure and privacy-compliant data and information sharing, and government regulations. Our results also indicate cybersecurity trends and allow to derive directions for future research and innovation activities that will be of high importance for Europe. Simone Fischer-Hübner, Cristina Alcaraz, Afonso Ferreira, Carmen Fernández Gago, Javier López 0001, Evangelos P. Markatos, Lejla Islami, Mahdi Akil |
J. Inf. Secur. Appl. | 4 |
| 2020 | A Model Specification Implementation for Trust Negotiation
Martin Kolár, Carmen Fernández Gago, Javier López 0001 |
NSS | 2 |
| 2019 | A Segregated Architecture for a Trust-based Network of Internet of ThingsabstractWith the ever-increasing number of smart home devices, the issues related to these environments are also growing. With an ever-growing attack surface, there is no standard way to protect homes and their inhabitants from new threats. The inhabitants are rarely aware of the increased security threats that they are exposed to and how to manage them. To tackle this problem, we propose a solution based on segmented architectures similar to the ones used in industrial systems. In this approach, the smart home is segmented into various levels, which can broadly be categorised into an inner level and external level. The external level is protected by a firewall that checks the communication from/to the Internet to/from the external devices. The internal level is protected by an additional firewall that filters the information and the communications between the external and the internal devices. This segmentation guarantees a trusted environment among the entities of the internal network. In this paper, we propose an adaptive trust model that checks the behaviour of the entities and in case the entities violate trust rules they can be put in quarantine or banned from the network. Davide Ferraris, Carmen Fernández Gago, Joshua Daniel, Javier López 0001 |
CCNC | 2 |
| 2019 | A model specification for the design of trust negotiations
Martin Kolár, Carmen Fernández Gago, Javier López 0001 |
Comput. Secur. | 2 |
| 2018 | Policy Languages and Their Suitability for Trust Negotiation
Martin Kolár, Carmen Fernández Gago, Javier López 0001 |
DBSec | 2 |
| 2018 | Modelling privacy-aware trust negotiations
Ruben Rios, Carmen Fernández Gago, Javier López 0001 |
Comput. Secur. | 2 |
| 2017 | Modelling trust dynamics in the Internet of Things
Carmen Fernández Gago, Francisco Moyano, Javier López 0001 |
Inf. Sci. | 1 |
| 2016 | Eliciting metrics for accountability of cloud systems
David Nuñez 0001, Carmen Fernández Gago, Jesus Luna |
Comput. Secur. | 2 |
| 2016 | A model-driven approach for engineering trust and reputation into software services
Francisco Moyano, Carmen Fernández Gago, Javier López 0001 |
J. Netw. Comput. Appl. | 2 |
| 2014 | Trust-Aware Decision-Making Methodology for Cloud Sourcing
Francisco Moyano, Kristian Beckers, Carmen Fernández Gago |
CAiSE | 3 |
| 2013 | Detecting Insider Threats: A Trust-Aware FrameworkabstractThe number of insider threats hitting organizations and big enterprises is rapidly growing. Insider threats occur when trusted employees misuse their permissions on organizational assets. Since insider threats know the organization and its processes, very often they end up undetected. Therefore, there is a pressing need for organizations to adopt preventive mechanisms to defend against insider threats. In this paper, we propose a framework for insiders identification during the early requirement analysis of organizational settings and of its IT systems. The framework supports security engineers in the detection of insider threats and in the prioritization of them based on the risk they represent to the organization. To enable the automatic detection of insider threats, we extend the SI* requirement modeling language with an asset model and a trust model. The asset model allows associating security properties and sensitivity levels to assets. The trust model allows specifying the trust level that a user places in another user with respect to a given permission on an asset. The insider threats identification leverages the trust levels associated with the permissions assigned to users, as well as the sensitivity of the assets to which access is granted. We illustrate the approach based on a patient monitoring scenario. Federica Paci, Carmen Fernández Gago, Francisco Moyano |
ARES | 2 |
| 2013 | A Metamodel for Measuring Accountability Attributes in the CloudabstractCloud governance, and in particular data governance in the cloud, relies on different technical and organizational practices and procedures, such as policy enforcement, risk management, incident management and remediation. The concept of accountability encompasses such practices, and is essential for enhancing security and trustworthiness in the cloud. Besides this, proper measurement of cloud services, both at a technical and governance level, is a distinctive aspect of the cloud computing model. Hence, a natural problem that arises is how to measure the impact on accountability of the procedures held in practice by organizations that participate in the cloud ecosystem. In this paper, we describe a metamodel for addressing the problem of measuring accountability properties for cloud computing, as discussed and defined by the Cloud Accountability Project (A4Cloud). The goal of this metamodel is to act as a language for describing: (i) accountability properties in terms of actions between entities, and (ii) metrics for measuring the fulfillment of such properties. It also allows the recursive decomposition of properties and metrics, from a high-level and abstract world to a tangible and measurable one. Finally, we illustrate our proposal of the metamodel by modelling the transparency property, and define some metrics for it. David Nuñez 0001, Carmen Fernández Gago, Siani Pearson, Massimo Felici |
CloudCom (1) | 2 |
| 2013 | A framework for enabling trust requirements in social cloud applications
Francisco Moyano, Carmen Fernández Gago, Javier López 0001 |
Requir. Eng. | 2 |
| 2012 | A Conceptual Framework for Trust Models
Francisco Moyano, Carmen Fernández Gago, Javier López 0001 |
TrustBus | 2 |
| 2010 | Trust management systems for wireless sensor networks: Best practices
Javier López 0001, Rodrigo Roman, Isaac Agudo, Carmen Fernández Gago |
Comput. Commun. | 4 |
| 2009 | Adaptive Dispatching of Incidences Based on Reputation for SCADA Systems
Cristina Alcaraz, Isaac Agudo, Carmen Fernández Gago, Rodrigo Roman, Gerardo Fernandez, Javier López 0001 |
TrustBus | 3 |
| 2009 | Concurrent access control for multi-user and multi-processor systems based on trust relationshipsabstractAbstract Concurrent access control is an old problem in many fields in Computer Science. It has been solved in many languages and systems, using mechanisms like monitors or priority queues. Nowadays computers implement multi‐core capabilities. This means that they are virtually capable of execution of processes in parallel. This requires new techniques and open new issues in the field of concurrent access control. Moreover, most operating systems are multi‐user; thus, we have to focus on a multi‐processor multi‐user scenario. Trust becomes a paramount aspect when building distributed applications; the same applies on a lower scale in modern computers. We propose the use of a trust graph that keeps record of the trust relationships of the system and helps in deciding on concurrent access requests. The information encoded in the graph will be used both in order to decide on the access requests and to order granted requests in terms of their associated trust level. Copyright © 2009 John Wiley & Sons, Ltd. Isaac Agudo, Carmen Fernández Gago, Javier López 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2008 | A Model for Trust Metrics Analysis
Isaac Agudo, Carmen Fernández Gago, Javier López 0001 |
TrustBus | 2 |
| 2005 | First-Order Temporal Verification in Practice
Carmen Fernández Gago, Ullrich Hustadt, Clare Dixon, Michael Fisher 0001, Boris Konev |
J. Autom. Reason. | 1 |
| 2004 | Using Temporal Logics of Knowledge in the Formal Verification of Security ProtocolsabstractTemporal logics of knowledge are useful for reasoning about situations where the knowledge of an agent or component is important, and where change in this knowledge may occur over time. Here we use temporal logics of knowledge to reason about security protocols. We show how to specify part of the Needham-Schroeder protocol using temporal logics of knowledge and prove various properties using a clausal resolution calculus for this logic. Clare Dixon, Carmen Fernández Gago, Michael Fisher 0001, Wiebe van der Hoek |
TIME | 2 |