Manuel A. Serrano

dblp:61/4664 · also Manuel Ángel Serrano, Manuel Ángel Serrano Martín · DBLP profile ↗
← Back
23ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0003-0962-5659ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 11 · 5 first-author · 4 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Systems, architecture and hardware · 1Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Operational fairness diagnostics for AI-based detection systems: Metrics and methodology
abstract
AI systems operating in complex, high-frequency environments often make critical decisions such as generating alerts, prioritizing events or assigning severity scores , under conditions of partial ground truth , uneven group visibility and implicit, context-dependent logic. In such settings, it becomes difficult to assess whether behavior is consistent across sources, categories or technical modules. This challenge is particularly relevant in domains such as cybersecurity, where automated decisions directly influence threat prioritization, resource allocation and system-level risk exposure. Fairness metrics have been extensively studied in machine learning, yet most approaches assume supervised classification tasks with complete labels and explicit demographic groups. These assumptions often break down in operational AI systems, where decisions are decentralized, labels are partial or delayed, and group-defining attributes are technical , such as protocol type, sensor origin or detection source. As a result, classical fairness metrics often fail to detect or characterize structural disparities in real-world, partially supervised deployments. To address this gap, we propose a structured six-phase methodology for adapting fairness metrics, specifically independence , separation and sufficiency , to decision systems operating under dynamic and context-sensitive conditions. The framework is applied to the domain of cybersecurity, where the analysis of system behavior is challenged by alert inflation, detection imbalance and score inconsistency. The metrics are characterized using four synthetic scenarios, crafted to reproduce typical diagnostic conditions and to verify the selective sensitivity of each metric, and a real-world intrusion detection dataset (UNSW-NB15), in which a trained Random Forest classifier is evaluated via 5-fold stratified cross-validation to reflect operational conditions. Results show that, even under a high-performing classifier (global F1 = 0.98), the proposed metrics reveal protocol-level disparities not captured by aggregate performance measures, and remain stable under consistency-preserving conditions. Statistical testing confirms that the observed disparities are highly significant ( p < 1 0 − 300 ), with effect size analysis confirming their practical magnitude, and comparative analysis with standard fairness metrics reveals the limited diagnostic resolution of these classical indicators in operational settings . The resulting metrics are mutually compatible and respond independently across decision dimensions without conflict. Their interpretability and traceability support structured diagnostic analysis of system behavior. We formally derive their theoretical properties , and discuss how they complement the diagnostic objectives promoted by governance frameworks such as the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001. These results position the resulting metrics as diagnostic instruments for analyzing system-level behavior in environments characterized by partial supervision and evolving behavior .
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
Knowl. Based Syst.2
2025 Early detection of backdoor attacks in federated learning via ecosystemic symmetry breaking
abstract
Evasive poisoning attacks such as semantic backdoors pose a growing threat to federated learning because they mimic benign client updates and evade detectors under secure aggregation. We introduce an unsupervised, per-client structural check that runs after each local round, before aggregation, requiring only compact statistical summaries derived from each client update after a geometric transformation that removes dependence on the global model. Client-update statistics are compared against a calibrated benign reference, and deviations are detected through statistical distances. Energy and Wasserstein-1 jointly define an operational pattern where threshold exceedances across projections reveal structural deviations even in apparently benign updates. Evaluated on canonical backdoor scenarios from Bagdasaryan et al., the method detects both strong and stealthy attacks in the first local round through consistent multi-projection threshold excesses, while benign updates show only isolated ones. The procedure is lightweight, unsupervised, compatible with secure aggregation, and does not require trigger datasets. By providing early per-client warnings before aggregation, it complements classical defenses such as norm clipping, differential privacy, and robust aggregation, enabling proactive mitigation of poisoning in federated learning.
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
BDCAT2
2025 Design and Development of a Predictive Security Threat Management System Leveraging CWEs, CVEs, and CAPECs
abstract
Organizations increasingly rely on digital platforms to support their operations, decision-making processes, and the delivery of critical services. This growing dependence has expanded their exposure to cyber threats that jeopardize the confidentiality, integrity, avail-ability, and operational continuity of information systems. This paper presents a system specifically designed to support the identi- fication and management of risks in technological infrastructures. The proposed solution collects vulnerability data daily from official sources and correlates it with the organization’s assets, enabling the prioritization of risks according to their criticality level. Further-more, the system integrates a prediction module based on machine learning techniques, capable of estimating the aggregated evolu- tion of risk for the following month. This predictive capability facilitates preventive decision-making and strengthens proactive cybersecurity risk management strategies.
Joaquín Sierra-Granados, José L. Ruiz-Catalán, David Garcia Rosado, Manuel A. Serrano
BDCAT4
2025 Guided and Federated RAG: Architectural Models for Trustworthy AI in Data Spaces
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
IDEAL (2)2
2025 Towards a methodology for ethical artificial intelligence system development: A necessary trustworthiness taxonomy
abstract
Recently, generative artificial intelligence (GenAI) has arisen and been rapidly adopted; due to its emergent abilities, there is a significantly increased need for risk management in the implementation of such systems. At the same time, many proposals for translating ethics into AI, as well as the first agreements by regulators governing the use of artificial intelligence (AI), have surfaced. This underscores the need for Trustworthy AI, which implies reliability, compliance, and ethics. However, there is still a lack of unified criteria, and more critically, a lack of systematic methodologies for operationalizing trustworthiness within AI development processes . Trustworthiness is crucial, as it ensures that the system performs consistently under expected conditions while adhering to moral and legal standards. The problem of ensuring trustworthiness must be addressed as a preliminary step in creating a methodology for building AI systems with these desirable features. Based on a systematic literature review (SLR), we analyze the ethical, legal, and technological challenges that AI projects face , identifying key considerations and gaps in current approaches. This article presents a detailed and structured sociotechnical taxonomy related to the concept of Trustworthy AI, grounded in the analysis of all relevant texts on the topic, and designed to enable the systematic integration of ethical, legal, and technological principles into AI development processes. The taxonomy establishes a sociotechnical foundation that reflects the interconnected nature of technological, ethical, and legal considerations, and serves as the conceptual basis for CRISP-TAI, a proposed specialized development lifecycle currently under validation, aimed at systematically operationalizing trustworthiness principles across all phases of AI system engineering.
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
Expert Syst. Appl.2
2025 Preface for "Quantum Programming for Software Engineering (QP4SE)"
Fabiano Pecorelli, Vita Santa Barletta, Manuel A. Serrano
Sci. Comput. Program.3
2025 Generation of Quantum Software From Truth Tables
abstract
ABSTRACT Background Quantum Computing (QC) represents a disruptive paradigm in computing, with significant implications across various domains such as medicine, logistics, chemistry, and defense. However, quantum software development—the discipline that enables the exploitation of QC's potential—faces considerable challenges due to the inherent complexity of quantum mechanics. Objective This work aims to facilitate the systematic development of quantum software by introducing a method aligned with classical software engineering principles, particularly the analysis and synthesis phases, through the automated generation and optimization of quantum circuit components. Methods The proposed approach focuses on the automated generation of quantum circuit components whose behavior can be formally described using truth tables. To this end, (i) a set of algorithms for the automatic generation of components is introduced, (ii) an optimization algorithm is developed to improve the efficiency of the generated components, and (iii) an automated support system is provided, allowing users to specify truth tables through multiple modeling strategies. Results The resulting system enables a structured and automated process for building reusable quantum circuit components, reducing manual effort and supporting higher abstraction levels in quantum programming. The design of the system adheres to foundational principles of Software Engineering, including agnosticism and automatic code generation. Conclusions This proposal contributes to quantum software development by providing a practical, engineering‐driven methodology for generating and optimizing quantum circuit components, thereby improving the efficiency, scalability, and accessibility of quantum programming practices.
Macario Polo, Ignacio García Rodríguez de Guzmán, Manuel A. Serrano, Mario Piattini
Softw. Pract. Exp.3
2024 Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals
abstract
Abstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process.
Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina
Frontiers Comput. Sci.4
2024 Exploring the trade-off between computational power and energy efficiency: An analysis of the evolution of quantum computing and its relation to classical computing
abstract
Quantum computing is considered a revolutionary technology due to its ability to solve computational problems that are beyond the capabilities of classical computers. However, quantum computing requires great amounts of energy to run. Therefore, a factor in deciding whether to use quantum computing should be not only the complexity of the problem to be solved, but also the energy required to solve it. This paper presents an empirical study developed with the aim of comparing classical and quantum computing in terms of energy efficiency to determine whether the increased power of quantum computers is offset by their higher energy consumption. To achieve this, a variety of problems with different levels of complexity were tested on both types of computers. Specifically, we used the IBM Quantum computers with a maximum of 5 qubits and an Intel i7, as a classical computer. In addition to this we have also analysed the evolution of the quantum computers, performing measurements on three time periods. Our empirical study showed that there is a variability of results obtained in the three time periods and that quantum computing is not recommended for low-complexity problems, given its high energy consumption, particularly when compared to traditional computing.
Elena Desdentado Fernández, Coral Calero, María Ángeles Moraga, Manuel A. Serrano, Félix García 0001
J. Syst. Softw.4
2024 Minimizing incident response time in real-world scenarios using quantum computing
abstract
Abstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA).
Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina
Softw. Qual. J.1
2021 MARISMA-BiDa pattern: Integrated risk analysis for big data
David Garcia Rosado, Julio Moreno, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Manuel A. Serrano, Eduardo Fernández-Medina
Comput. Secur.5
2020 Application of security reference architecture to Big Data ecosystems in an industrial scenario
abstract
Summary Big Data environments are typically very complex ecosystems; this means that implementing them is complicated. One possible technique with which to address this complexity is the use of abstraction. Reference architecture (RA) can be useful for an improved understanding of the main components of Big Data. Herein, we propose a security RA that includes the management of security concerns and provides the main elements of a Big Data ecosystem. Application of this architecture to real‐world scenarios facilitates its refinement and improves its usefulness. In this article, we present a case study of a real‐world Big Data ecosystem implemented in a banking environment. This ecosystem was developed by everis, an NTT company with which we collaborated for this study. To conduct this validation case study, a map was established between the elements of the Big Data ecosystem implemented and our proposal. Consequently, a series of valuable lessons that can improve both our architecture and the security of the Big Data environment were obtained. These include recommendations for a set of best practices such as the use of security patterns.
Julio Moreno, Manuel A. Serrano, Eduardo B. Fernández, Eduardo Fernández-Medina
Softw. Pract. Exp.3
2018 Towards a Security Reference Architecture for Big Data
Julio Moreno, Manuel A. Serrano, Eduardo Fernández-Medina, Eduardo B. Fernández
DOLAP2
2016 A Data Quality in Use model for Big Data
Jorge Merino, Ismael Caballero 0001, Bibiano Rivas, Manuel A. Serrano, Mario Piattini
Future Gener. Comput. Syst.4
2016 Empowering global software development with business intelligence
Alejandro Maté, Juan Trujillo 0001, Félix García 0001, Manuel A. Serrano, Mario Piattini
Inf. Softw. Technol.4
2008 Empirical studies to assess the understandability of data warehouse schemas using structural metrics
Manuel A. Serrano, Coral Calero, Houari Sahraoui, Mario Piattini
Softw. Qual. J.1
2007 A Proposal for a Conceptual Data Warehouse Quality Model
Manuel A. Serrano, Rafael Romero 0001, Jose-Norberto Mazón, Juan Trujillo 0001, Mario Piattini
SEKE1
2007 Metrics for data warehouse conceptual models understandability
Manuel A. Serrano, Juan Trujillo 0001, Coral Calero, Mario Piattini
Inf. Softw. Technol.1
2007 Managing software process measurement: A metamodel-based approach
Félix García 0001, Manuel A. Serrano, José A. Cruz-Lemus, Francisco Ruiz 0001, Mario Piattini
Inf. Sci.2
2005 A Set of Quality Indicators and Their Corresponding Metrics for Conceptual Models of Data Warehouses
Gemma Berenguer, Rafael Romero 0001, Juan Trujillo 0001, Manuel A. Serrano, Mario Piattini
DaWaK4
2005 Applying MDA to the development of data warehouses
abstract
Different modeling approaches have been proposed to overcome every design pitfall of the development of the different parts of a data warehouse (DW) system. However, they are all partial solutions which deal with isolated aspects of the DW and do not provide designers with an integrated and standard method for designing the whole DW (ETL processes, data sources, DW repository and so on). On the other hand, the Model Driven Architecture (MDA) is a standard framework for software development that addresses the complete life cycle of designing, deploying, integrating, and managing applications by using models in software development. In this paper, we describe how to align the whole DW development process to MDA. Then, we define MD2A (MultiDimensional Model Driven Architecture), an approach for applying the MDA framework to one of the stages of the DW development: multidimensional (MD) modeling. First, we describe how to build the different MDA artifacts (i.e. models) by using extensions of the Unified Modeling Language (UML). Secondly, transformations between models are clearly and formally established by using the Query/View/Transformation (QVT) approach. Finally, an example is provided to better show how to apply MDA and its transformations to the MD modeling.
Jose-Norberto Mazón, Juan Trujillo 0001, Manuel A. Serrano, Mario Piattini
DOLAP3
2004 Empirical Validation of Metrics for Conceptual Models of Data Warehouses
Manuel A. Serrano, Coral Calero, Juan Trujillo 0001, Sergio Luján-Mora, Mario Piattini
CAiSE1
2004 Datawarehouses design: effectivity of the star schema
Coral Calero, Manuel A. Serrano, Mario Piattini
SEKE2