VLDB 2026 Research / reviewers in the wild / expert
Aitor Urbieta
dblp:63/4658
· DBLP profile ↗
17ranked-venue papers
1as first author
11since 2021 · last 2025
0000-0001-5836-4198ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 8 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Mitigation of PFCP Attacks in 5G Networks: Dynamic Defense Through Moving Target Defense and Honeynets
Aitor Landa-Arrue, Jasone Astorga, Iñaki Garitano, Aitor Urbieta |
ARES (1) | 4 |
| 2025 | Flashy Backdoor: Real-world Environment Backdoor Attack on SNNs with DVS CamerasabstractWhile security vulnerabilities in traditional Deep Neural Networks have been extensively studied, the susceptibility of Spiking Neural Networks (SNNs) to adversarial attacks remains mostly underexplored. In fact, until now, the mechanisms for injecting backdoors into SNN models have been limited to digital scenarios. In this work, we present the first evaluation of backdoor attacks on SNN models in real-world physical environments, using event-based Dynamic Vision Sensor cameras. We assess and identify the limitations of existing backdoors in physical settings. To address each limitation, we develop three novel backdoor attack methods on SNNs, i.e., Framed, Strobing, and Flashy Backdoor, each progressively enhancing attack effectiveness and physical transferability. Our methods achieve up to a 100% Attack Success Rate with a negligible drop in clean accuracy across all tested datasets. We adapt and evaluate the effectiveness of state-of-the-art backdoor defenses from the image domain for SNNs. Next, we assess trigger stealthiness with commonly used metrics, finding them highly stealthy. Finally, we propose alternative detection techniques better suited for neuromorphic data. The code, new dataset, and results are available in our repository.11https://github.com/Yencr0s/Flashy_backdoor Roberto Riaño, Gorka Abad, Stjepan Picek, Aitor Urbieta |
ACSAC | 4 |
| 2025 | Time-Distributed Backdoor Attacks on Federated Spiking Learning
Gorka Abad, Stjepan Picek, Aitor Urbieta |
ESORICS (1) | 3 |
| 2024 | Penetration Testing of 5G Core Network Web TechnologiesabstractThanks to technologies such as virtual network function the Fifth Generation (5G) of mobile networks dynamically allocate resources to different types of users in an on-demand fashion. Virtualization extends up to the 5G core, where software-defined networks and network slicing implement a customizable environment. These technologies can be controlled via application programming interfaces and web technologies, inheriting hence their security risks and settings. An attacker exploiting vulnerable implementations of the 5G core may gain privileged control of the network assets and disrupt its availability. However, there is currently no security assessment of the web security of the 5G core network. In this paper, we present the first security assessment of the 5G core from a web security perspective. We use the STRIDE threat modeling approach to define a complete list of possible threat vectors and associated attacks. Thanks to a suite of security testing tools, we cover all of these threats and test the security of the 5G core. In particular, we test the three most relevant open-source 5G core implementations, i.e., Open5GS, Free5Gc, and OpenAir Interface. Our analysis shows that all these cores are vulnerable to at least two of our identified attack vectors, demanding increased security measures in the development of future 5G core networks. Filippo Giambartolomei, Marc Barcelo, Alessandro Brighente, Aitor Urbieta, Mauro Conti |
ICC | 4 |
| 2024 | Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data
Gorka Abad, Oguzhan Ersoy, Stjepan Picek, Aitor Urbieta |
NDSS | 4 |
| 2024 | Smart Contract Powered Framework for the Next Generation Industry 4.0 Business ModelabstractBlockchain stands as a crucial technology capable of enhancing transparency, security, and efficiency within various sectors. Particularly in Industry 4.0, blockchains can be employed to monitor the movement of goods and materials across the supply chain, ensuring data integrity, transparency, immutability, accountability, and industrial process interoperability. Industry 4.0 companies must interact with various external players, which often requires collaborations and partnerships to access new technologies, shared data and analytics, and required resources for their processes. However, current business process management in the industry is mostly centralized, untraceable, unreliable and lacks automation. Smart contracts hold the potential to tackle these concerns by offering a remarkable level of automation, transparency, and security while also aiding in regulatory compliance. However, the adoption of smart contracts in Industry 4.0 is still limited due to various obstacles. The challenges facing the deployment of Distributed Ledger Technology (DLT) in Industry 4.0 are multifaceted, encompassing issues such as interoperability across different blockchain systems, scalability and performance constraints, limitations on ensuring data privacy, difficulties in accessing external data sources, and the significant transaction costs often associated with executing smart contracts. To tackle these obstacles comprehensively, we advocate for the development of an interoperable consortium blockchain framework tailored to meet the versatile business processes required by Industry 4.0 enterprises or groups. This proposed architecture, distinct from any specific internal system, incorporates private channels and ensures secure access to external data, thus addressing broader interoperability concerns beyond just smart contracts. Our goal is to establish a comprehensive DLT framework that assures data integrity and traceability throughout its lifecycle, from creation and processing to its final utilization for business insights. The effectiveness of our approach is demonstrated through its application in a real-world industrial scenario, undertaken in partnership with Fagor Automation, a global leader in the industrial sector. Denis Stefanescu, Leticia Montalvillo-Mendizabal, Aitor Urbieta, Patxi Galán-García, Juanjo Unzilla |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2024 | End to End secure data exchange in value chains with dynamic policy updates
Aintzane Mosteiro-Sanchez, Marc Barcelo, Jasone Astorga, Aitor Urbieta |
Future Gener. Comput. Syst. | 4 |
| 2024 | Gotham Testbed: A Reproducible IoT Testbed for Security Experiments and Dataset GenerationabstractThe growing adoption of the Internet of Things (IoT) has brought a significant increase in attacks targeting those devices. Machine learning (ML) methods have shown promising results for intrusion detection; however, the scarcity of IoT datasets remains a limiting factor in developing ML-based security systems for IoT scenarios. Static datasets get outdated due to evolving IoT architectures and threat landscape; meanwhile, the testbeds used to generate them are rarely published. This paper presents the Gotham testbed, a reproducible and flexible security testbed extendable to accommodate new emulated devices, services or attackers. Gotham is used to build an IoT scenario composed of 100 emulated devices communicating via MQTT, CoAP and RTSP protocols, among others, in a topology composed of 30 switches and 10 routers. The scenario presents three threat actors, including the entire Mirai botnet lifecycle and additional red-teaming tools performing DoS, scanning, and attacks targeting IoT protocols. The testbed has many purposes, including a cyber range, testing security solutions, and capturing network and application data to generate datasets. We hope that researchers can leverage and adapt Gotham to include other devices, state-of-the-art attacks and topologies to share scenarios and datasets that reflect the current IoT settings and threat landscape. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Federated Explainability for Network Anomaly CharacterizationabstractMachine learning (ML) based systems have shown promising results for intrusion detection due to their ability to learn complex patterns. In particular, unsupervised anomaly detection approaches offer practical advantages as does not require labeling the training data, which is costly and time-consuming. To further address practical concerns, there is a rising interest in adopting federated learning (FL) techniques as a recent ML model training paradigm for distributed settings (e.g., IoT), thereby addressing challenges such as data privacy, availability and communication cost concerns. However, output generated by unsupervised models provide limited contextual information to security analysts at SOCs, as they usually lack the means to know why a sample was classified as anomalous or cannot distinguish between different types of anomalies, difficulting the extraction of actionable information and correlation with other indicators. Moreover, ML explainability methods have received little attention in FL settings and present additional challenges due to the distributed nature and data locality requirements. This paper proposes a new methodology to characterize and explain the anomalies detected by unsupervised ML-based intrusion detection models in FL settings. We adapt and develop explainability, clustering and cluster validation algorithms to FL settings to mine patterns in the anomalous samples and identify different threats throughout the entire network, demonstrating the results on two network intrusion detection datasets containing real IoT malware, namely Gafgyt and Mirai, and various attack traces. The learned clustering results can be used to classify emerging anomalies, provide additional context that can be leveraged to gain more insight and enable the correlation of the anomalies with alerts triggered by other security solutions. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
RAID | 4 |
| 2023 | Clustered federated learning architecture for network anomaly detection in large scale heterogeneous IoT networksabstractThere is a growing trend of cyberattacks against Internet of Things (IoT) devices; moreover, the sophistication and motivation of those attacks is increasing. The vast scale of IoT, diverse hardware and software, and being typically placed in uncontrolled environments make traditional IT security mechanisms such as signature-based intrusion detection and prevention systems challenging to integrate. They also struggle to cope with the rapidly evolving IoT threat landscape due to long delays between the analysis and publication of the detection rules. Machine learning methods have shown faster response to emerging threats; however, model training architectures like cloud or edge computing face multiple drawbacks in IoT settings, including network overhead and data isolation arising from the large scale and heterogeneity that characterizes these networks. This work presents an architecture for training unsupervised models for network intrusion detection in large, distributed IoT and Industrial IoT (IIoT) deployments. We leverage Federated Learning (FL) to collaboratively train between peers and reduce isolation and network overhead problems. We build upon it to include an unsupervised device clustering algorithm fully integrated into the FL pipeline to address the heterogeneity issues that arise in FL settings. The architecture is implemented and evaluated using a testbed that includes various emulated IoT/IIoT devices and attackers interacting in a complex network topology comprising 100 emulated devices, 30 switches and 10 routers. The anomaly detection models are evaluated on real attacks performed by the testbed’s threat actors, including the entire Mirai malware lifecycle, an additional botnet based on the Merlin command and control server and other red-teaming tools performing scanning activities and multiple attacks targeting the emulated devices. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
Comput. Secur. | 4 |
| 2022 | Poster: Backdoor Attacks on Spiking NNs and Neuromorphic DatasetsabstractNeural networks provide state-of-the-art results in many domains. Yet, they often require high energy and time-consuming training processes. Therefore, the research community is exploring alternative, energy-efficient approaches likespiking neural networks (SNNs). SNNs mimic brain neurons by encoding data into sparse spikes, resulting in energy-efficient computing. To exploit the properties of the SNNs, they can be trained with neuromorphic datasets that capture the differences in motion. SNNs, just like any neural network model, can be susceptible to security threats that make the model perform anomalously. One of the most crucial threats is the backdoor attacks that modify the training set to inject a trigger in some samples. After training, the neural network will perform correctly on the main task. However, under the presence of the trigger (backdoor) on an input sample, the attacker can control its behavior. The existing works on backdoor attacks consider standard datasets and not neuromorphic ones. In this paper, to the best of our knowledge, we present the first backdoor attacks on neuromorphic datasets. Due to the structure of neuromorphic datasets, we utilize two different triggers, i.e., static andmoving triggers. We then evaluate the performance of our backdoor using spiking neural networks, achieving top accuracy on both main and backdoor tasks, up to 99%. Gorka Abad, Oguzhan Ersoy, Stjepan Picek, Víctor Julio Ramírez-Durán, Aitor Urbieta |
CCS | 5 |
| 2020 | A model-based approach for developing event-driven architectures with AsyncAPIabstractIn this Internet of Things (IoT) era, our everyday objects have evolved into the so-called cyber-physical systems (CPS). The use and deployment of CPS has especially penetrated the industry, giving rise to the Industry 4.0 or Industrial IoT (IIoT). Typically, architectures in IIoT environments are distributed and asynchronous, communication being guided by events such as the publication of (and corresponding subscription to) messages. Abel Gómez 0001, Markel Iglesias-Urkia, Aitor Urbieta, Jordi Cabot |
MoDELS | 3 |
| 2019 | TRILATERAL: Software Product Line based Multidomain IoT Artifact Generation for Industrial CPS
Aitziber Iglesias, Markel Iglesias-Urkia, Beatriz López-Davalillo, Santiago Charramendieta, Aitor Urbieta |
MODELSWARD | 5 |
| 2019 | Integrating Electrical Substations Within the IoT Using IEC 61850, CoAP, and CBORabstractElectrical substations are crucial elements of Smart Grids (SGs), where they are mainly responsible for voltage transformations. However, due to the integration of distributed energy resources in the grid, substations now have to provide additional grid management capabilities which in turn require supervision and automation solutions for large low-voltage grids. A recurring challenge in such deployments are siloed systems that are due to noninteroperable communication protocols across substations: although most substations' communication is based on the International Electrotechnical Commission (IEC) 61850 standard, deployed legacy protocols lag behind modern communication technologies in terms of performance, hindering the full transition to lightweight protocols. This paper demonstrates that IEC 61850 can be fully mapped to the Constrained Application Protocol (CoAP) in combination with the Concise Binary Object Representation (CBOR) format while improving system performance compared to existing alternatives [e.g., WS-SOAP and Hypertext Transfer Protocol (HTTP)]. On average, CoAP+CBOR needs 44% and 18% of the message size and 71% and 85% of the time compared to systems based on HTTP and WS-* Web services, respectively-this is especially relevant for resource-constrained devices and networks in electrical grids. In addition, CoAP is based on the Representational State Transfer (REST) architectural style, which supports system integration and interoperability through uniform identification and interaction. This approach fosters the standard-compliant integration of legacy platforms with modern substations as well as current IoT systems in neighboring domains, such as building management and infrastructure automation systems. Markel Iglesias-Urkia, Diego Casado Mansilla, Simon Mayer, Josu Bilbao, Aitor Urbieta |
IEEE Internet Things J. | 5 |
| 2018 | Validation of a CoAP to IEC 61850 Mapping and Benchmarking vs HTTP-REST and WS-SOAPabstractWith the advent of Smart Grid systems, the digitalization of electrical grid infrastructures aims to improve energy saving and efficiency. The International Electrotechnical Commission (IEC) is one of the organizations that create and manage norms and standards in areas related to electricity and electronics, such as IEC 61850. In recent years, the research community have proposed mappings of different communication protocols to IEC 61850. However, most of the proposals focused on heavyweight interaction paradigms and protocols such as Common Object Request Broker Architecture (CORBA), Data Distribution Service (DDS), HTTP-REST or Web Services. With the proliferation of the Internet of Things (IoT), new lightweight protocols are appearing opening new perspectives to the standard. Hence, this paper firstly presents a validation of a mapping of the IEC 61850 standard to the Constrained Application Protocol (CoAP) and then compares its performance implementing the IEC's mapping against HTTP-REST and Web Services/SOAP. For comparison purposes, the communication latency, the number of total bytes sent, and the size of the overhead are presented for each of the three approaches. To conclude, future perspectives on the suitability of lightweight protocols to the IEC 61850 are provided. Markel Iglesias-Urkia, Diego Casado Mansilla, Simon Mayer, Aitor Urbieta |
ETFA | 4 |
| 2017 | Adaptive and context-aware service composition for IoT-based smart cities
Aitor Urbieta, Alejandra N. González-Beltrán, Sonia Ben Mokhtar, M. Anwar Hossain 0001, Licia Capra |
Future Gener. Comput. Syst. | 1 |
| 2014 | Process Flexibility in Service Orchestration: A Systematic Literature ReviewabstractIn dynamic environments, changes are often unpredictable and complex. Process models cannot be fully specified up-front and process flexibility becomes a key issue. Enterprise applications and systems supporting such processes are increasingly being architected in a service-oriented style. In this light, our goal is to analyze service orchestration approaches from a process flexibility perspective. Through a systematic literature review, we evaluate 17 service orchestration approaches and analyze their support for: (i) variability, support for large collections of process variants, (ii) adaptation, need for instance changes during runtime, (iii) evolution, need for schema changes during runtime, and (iv) looseness, need for loosely-specified models. The review findings provide a clearer understanding of process flexibility requirements and service orchestration mechanisms that support them, helping us to understand the limitations and shed light on future research areas. Aitor Murguzur, Karmele Intxausti, Aitor Urbieta, Salvador Trujillo, Goiuria Sagardui Mendieta |
Int. J. Cooperative Inf. Syst. | 3 |