Roberto Rigolin Ferreira Lopes

dblp:71/8280 · also Roberto Rigolin F. Lopes · DBLP profile ↗
← Back
16ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-0114-5610ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Agentic Generative AI for Automation of Cyber Security Attack Chains in Tactical MANETs
abstract
Automating cyberattack simulations is useful for evaluating the cyber resilience of mission-critical infrastructures, such as Tactical Mobile Ad-Hoc Networks (MANETs). Traditional red teaming tools lack adaptability, integration, and scalability, which limits their applicability in dynamic military environments. This paper presents an agentic generative AI system combining Cybersecurity Knowledge Graphs (CSKGs) and Large Language Model (LLM) agents. This system autonomously generates and executes context-aware cyberattack chains. The system analyzes Cyber Threat Intelligence (CTI) data, attack tool documentation, and telemetry data to plan and orchestrate multi-stage attacks using tools such as Metasploit and Sliver within an emulated environment. This approach aligns with the Software-defined Defence (SDD) paradigm by enabling software-driven, mission-adaptive simulation of Advanced Persistent Threats (APTs). We evaluate the agent system in a controlled emulated scenario, demonstrating semi-automation from semantic threat representation to system-level exploitation involving human operators.
Johannes Loevenich, Roberto Rigolin Ferreira Lopes
LCN2
2025 Towards Robust Autonomous Cyber Defence Agents Using Hybrid AI Models
abstract
Recent developments in Software-Defined Defence (SDD) provide the interfaces for multi-layer monitoring and control to realise Autonomous Cyber Defence (ACD) in critical network infrastructure used by the military. As a result, autonomous agents can enforce cybersecurity measures at different layers (link, IP, transport and application) using hybrid Artificial Intelligence (AI) models. For example, Multi-Agent Reinforcement Learning (MARL) can be combined with symbolic AI (knowledge graphs) and augmented/fine-tuned Large Language Models (LLMs) to detect, predict, protect, respond and recover from cyberattacks. This thesis starts from the hypothesis that the robustness of ACD agents can be formally verified, ensuring their safe development in mission critical environments. By applying Formal Verification (FV) techniques to MARL systems, the aim is to provide mathematically grounded guarantees such as correctness, safety, and adversarial resilience, thereby enabling trustworthy autonomous decision-making in SDD-enabled infrastructures.
Laurin Holz, Johannes Loevenich, Roberto Rigolin Ferreira Lopes
NetSoft3
2025 A Hybrid Model for Network Condition Forecasting to Improve QoS in Tactical MANETs
abstract
This paper introduces a hybrid AI model designed to predict long-term network conditions in tactical Mobile Ad Hoc Networks (MANETs), with the goal of improving Quality of Service (QoS). Our hypothesis is that tactical MANETs can be modeled as chaotic systems representing ever-changing environments, which allows us to analyze the system using principles of chaotic time series theory. These principles refine the process of slicing the network into sequential snapshots, facilitating the prediction of future network dynamics through hybrid AI models. Our NetConF model integrates Graph Convolutional Networks (GCN), Gated Recurrent Units (CuDNNGRU), and an Encoder-Decoder architecture to predict future topology and network metrics. Additionally, a Deep Reinforcement Learning (DRL) model is used to optimize QoS metrics in the tactical network. Numerical results on three open datasets (Anglova, Asturieser, and Rotaxi) suggest that our model improves upon existing deep learning and transformer models in predicting the long-term evolution of MANETs. Furthermore, we show that dynamic network configurations can significantly benefit from this approach.
Johannes Loevenich, Tobias Hürten, Florian Spelter, Johannes Braun 0004, Erik Adler, Linnet Moxon, Roberto Rigolin Ferreira Lopes
NOMS7
2025 On the Challenges to Adapt to Ever-Changing Network Conditions in Tactical MANETs
abstract
This paper discusses the challenges of adapting IP flows to ever-changing network conditions in tactical mobile ad hoc networks (MANETs), and presents a solution that combines a slicing unit, a probabilistic Graph Convolutional Neural Network (GCN), and Deep Reinforcement Learning (DRL) to improve QoS in tactical communication systems. Our methodology consists of three interacting agents: an environment builder agent responsible for generating complex network topologies, a DRL agent located in the control plane that makes decisions based on information gathered from different layers of the multi-layer tactical system, and an adversary designed to improve the robustness of the DRL agent. Our experimental results indicate that the combination of GCNs and DRL, together with adversarial training, is a promising solution for improving the end-to-end Quality of Service (QoS) of modern tactical communication systems operating in hostile environments that may host active adversaries.
Johannes Loevenich, Roberto Rigolin Ferreira Lopes
NOMS2
2025 Design and evaluation of an Autonomous Cyber Defence agent using DRL and an augmented LLM
abstract
In this paper, we design and evaluate an Autonomous Cyber Defence (ACD) agent to monitor and act within critical network segments connected to untrusted infrastructure hosting active adversaries. We assume that modern network segments use software-defined controllers with the means to host ACD agents and other cybersecurity tools that implement hybrid AI models. Our agent uses a hybrid AI architecture that integrates deep reinforcement learning (DRL), augmented Large Language Models (LLMs), and rule-based systems. This architecture can be implemented in software-defined network controllers , enabling automated defensive actions such as monitoring, analysis, decoy deployment, service removal, and recovery. A core contribution of our work is the construction of three cybersecurity knowledge graphs that organise and map data from network logs, open source Cyber Threat Intelligence (CTI) reports, and vulnerability frameworks. These graphs enable automatic mapping of Common Vulnerabilities and Exposures (CVEs) to offensive tactics and techniques defined in the MITRE ATT&CK framework using Bidirectional Encoder Representations from Transformers (BERT) and Generative Pre-trained Transformer (GPT) models. Our experimental evaluation of the knowledge graphs shows that BERT-based models perform better, with precision (83.02%), recall (75.92%), and macro F1 scores (58.70%) significantly outperforming GPT models. The ACD agent was evaluated in a Cyber Operations Research (ACO) gym against eleven DRL models, including Proximal Policy Optimisation (PPO), Hierarchical PPO, and ensembles under two different attacker strategies. The results show that our ACD agent outperformed baseline implementations , with its DRL models effectively mitigating attacks and recovering compromised systems. In addition, we implemented and evaluated a chatbot using Retrieval-Augmented Generation (RAG) and a prompting agent augmented with the CTI reports represented in the cybersecurity knowledge graphs. The chatbot achieved high scores on generation metrics such as relevance (0.85), faithfulness (0.83), and semantic similarity (0.88), as well as retrieval metrics such as contextual precision (0.91). The experimental results suggest that the integration of hybrid AI systems with knowledge graphs can enable the automation and improve the precision of cyber defence operations, and also provide a robust interface for cybersecurity experts to interpret and respond to advanced cybersecurity threats.
Johannes Loevenich, Erik Adler, Tobias Hürten, Roberto Rigolin Ferreira Lopes
Comput. Networks4
2024 DRL meets GNN to improve QoS in Tactical MANETs
abstract
This paper proposes a hybrid AI model combining Graph Neural Network (GNN) and Deep Reinforcement Learning (DRL) to improve QoS in modern communication systems deployed to tactical networks. Our methodology consists of three interacting agents: an environment builder agent responsible for generating complex network graph environments, a DRL agent situated within the control plane that possesses a global view of the current network state and makes decisions based on information gathered from various layers of the multi-layer tactical system, and an adversary designed to improve the robustness of the DRL agent. Our initial results indicate that enabling GNNs and DRL together with adversarial training is a promising solution for enhancing the Quality of Service (QoS) of modern tactical communication systems operating in hostile environments that may host active adversaries.
Johannes Loevenich, Roberto Rigolin Ferreira Lopes
NOMS2
2023 DataFITS: A Heterogeneous Data Fusion Framework for Traffic and Incident Prediction
abstract
This paper introduces DataFITS (Data Fusion on Intelligent Transportation System), an open-source framework that collects and fuses traffic-related data from various sources, creating a comprehensive dataset. We hypothesize that a heterogeneous data fusion framework can enhance information coverage and quality for traffic models, increasing the efficiency and reliability of Intelligent Transportation System (ITS) applications. Our hypothesis was verified through two applications that utilized traffic estimation and incident classification models. DataFITS collected four data types from seven sources over nine months and fused them in a spatiotemporal domain. Traffic estimation models used descriptive statistics and polynomial regression, while incident classification employed the k-nearest neighbors (k-NN) algorithm with Dynamic Time Warping (DTW) and Wasserstein metric as distance measures. Results indicate that DataFITS significantly increased road coverage by 137% and improved information quality for up to 40% of all roads through data fusion. Traffic estimation achieved an$\text{R}^2$score of 0.91 using a polynomial regression model, while incident classification achieved 90% accuracy on binary tasks (incident or non-incident) and around 80% on classifying three different types of incidents (accident, congestion, and non-incident).
Philipp Zißner, Paulo H. L. Rettore, Bruno P. Santos, Johannes Loevenich, Roberto Rigolin Ferreira Lopes
IEEE Trans. Intell. Transp. Syst.5
2022 Road Traffic Density Estimation Based on Heterogeneous Data Fusion
abstract
This investigation starts with the hypothesis that fusing heterogeneous data sources can increase the data coverage and improve the accuracy of traffic-related applications in Intel-ligent Transportation Systems (ITS). Therefore, we designed (i) a Data Fusion on Intelligent Transportation Systems (DataFITS) framework that allows collecting data from numerous sources and fusing them according to spatial and temporal criteria; (ii) a traffic estimation method that groups road segments into regions, identify correlations between them, and measure the traffic distribution to estimate traffic. As a result, DataFITS increased by 130% the number of road segments coverage and enhanced, by fusion process, around 35% of road overlapping data sources. We evaluate the traffic estimation of the 15 most correlated regions, where the fused data together with correlated areas resulted in the best traffic estimation accuracy by reaching up to 40% in some cases and 9% on average.
Philipp Zißner, Paulo H. L. Rettore, Bruno P. Santos, Roberto Rigolin Ferreira Lopes, Peter Sevenich
ISCC4
2022 Queuing Over Ever-Changing Communication Scenarios in Tactical Networks
abstract
This paper introduces a hierarchy of queues complementing each other to handle ever-changing communication scenarios in tactical networks. The first queue stores the QoS-constrained messages from command and control systems. These messages are fragmented into IP packets, which are stored in a queue of packets (second) to be sent to the radio buffer (third), which is a queue with limited space therefore, open to overflow. We start with the hypothesis that these three queues can handle ever-changing user(s) data flows (problem$A$) through ever-changing network conditions (problem$B$) using cross-layer information exchange, such as buffer occupancy, data rate, queue size and latency (problem$A|B$). We introduce two stochastic models to create sequences of QoS-constrained messages ($A$) and to create ever-changing network conditions ($B$). In sequence, we sketch a control loop to shape$A$to$B\;$to test our hypothesis using model$A|B$, which defines enforcement points at the incoming/outgoing chains of the system together with a control plane. Then, we discuss experimental results in a network with VHF radios using data flows that overflows the radio buffer over ever-changing data rate patterns. We discuss quantitative results showing the performance and limitations of our solutions for problems$A$,$B$, and$A|B$.
Roberto Rigolin Ferreira Lopes, Pooja Hanavadi Balaraju, Paulo H. L. Rettore, Peter Sevenich
IEEE Trans. Mob. Comput.1
2020 Road Data Enrichment Framework Based on Heterogeneous Data Fusion for ITS
abstract
In this work, we propose the Road Data Enrichment (RoDE), a framework that fuses data from heterogeneous data sources to enhance Intelligent Transportation System (ITS) services, such as vehicle routing and traffic event detection. We describe RoDE through two services: (i) Route service, and (ii) Event service. For the first service, we present the Twitter MAPS (T-MAPS), a low-cost spatiotemporal model to improve the description of traffic conditions through Location-Based Social Media (LBSM) data. As a case study, we explain how T-MAPS is able to enhance routing and trajectory descriptions by using tweets. Our experiments compare T-MAPS' routes against Google Maps' routes, showing up to 62% of route similarity, even though T-MAPS uses fewer and coarse-grained data. We then propose three applications, Route Sentiment (RS), Route Information (RI), and Area Tags (AT), to enrich T-MAPS' suggested routes. For the second service, we present the Twitter Incident (T-Incident), a low-cost learning-based road incident detection and enrichment approach built using heterogeneous data fusion. Our approach uses a learning-based model to identify patterns on social media data which is then used to describe a class of events, aiming to detect different types of events. Our model to detect events achieved scores above 90%, thus allowing incident detection and description as a RoDE application. As a result, the enriched event description allows ITS to better understand the LBSM user's viewpoint about traffic events (e.g., jams) and points of interest (e.g., restaurants, theaters, stadiums).
Paulo H. L. Rettore, Bruno P. Santos, Roberto Rigolin Ferreira Lopes, Guilherme Maia, Leandro A. Villas, Antonio Alfredo Ferreira Loureiro
IEEE Trans. Intell. Transp. Syst.3
2019 Towards a Traffic Data Enrichment Sensor Based on Heterogeneous Data Fusion for ITS
abstract
In this work, we propose Traffic Data EnrichmentSensor (TraDES), towards a low-cost traffic sensor for Intelligent Transportation System (ITS) based on heterogeneous data fusion. TraDES aims at fusing data from vehicular traces with road traffic data to enrich current spatiotemporal traffic data. In that direction, we propose a robust methodology to group spatially and temporally these different data sources, producing a vehicular trace with its respective traffic conditions, which is given as input to a learning-based model based on Artificial Neural Networks (ANN). Hence, TraDES is an enriched traffic sensor that is able to sense (detect) traffic conditions using a scalable and low-cost approach and to increase the spatiotemporal traffic data coverage.
Paulo H. L. Rettore, Roberto Rigolin Ferreira Lopes, Guilherme Maia, Leandro A. Villas, Antonio Alfredo Ferreira Loureiro
DCOSS2
2017 Trade-off analysis of a service-oriented and hierarchical queuing mechanism
abstract
This paper sketches a service-oriented and hierarchical queuing mechanism designed to manage radio buffers while delivering web services. The goal is avoid buffer overflow implementing a three-level queuing mechanism. The first level is the message queue which stores messages from user-facing services. At the second level, the messages are fragmented into IP packets which are stored in the packet queue. Finally, the third level is the radio buffer itself. As a result, a multi-homed node has queues for each radio, capturing the likely differences of data rate, buffer size and current usage. A prototype based on web services was tested using real military radios; VHF radios with large coverage (~20 km) but very low data rate (2.4-9.6 kbps). We analyzed the trade-offs within the system configuration, targeting at an optimal and robust radio buffer management.
Roberto Rigolin Ferreira Lopes, Antti Viidanoja, Maximilien Lhotellier, Michal Mazurkiewicz, Giampaolo Melis, Anne Diefenbach, Tobias Ginzler, Norman Jansen
NCA1
2013 Social networks adding community-scale to context-aware connectivity management
abstract
People are accessing online social networks wherever they go through smartphones and tablets. These mobile devices are capable to sense, compute and communicate, allowing people to create and consume rich digital content anywhere. Popular social applications are attaching geographical localization to user-generated digital content, creating geo-tagged social media. Given the heterogeneity of current wireless environments (i.e., multiple access providers and communication technologies) it is challenging to keep mobile devices best connected anywhere. In this paper, a wireless connectivity manager is designed as a sensing system. The mobile device's wireless interfaces are the sensors and the collected context data is shared attached to geo-tagged social media. The goal was take advantage of popular location-based web applications to delivery connectivity context data within social circles. As part of a sensing system, online social networks adds scale to the system and allow collaboration around fresh, local, personalized and social context data. Simulations were performed to quantify how collaboration evolves, to discover connectivity opportunities in a specific place, as function of community size and users mobility patterns.
Roberto Rigolin Ferreira Lopes
WCNC1
2012 Social and location-based collaboration mechanism to manage wireless connectivity context data
abstract
This paper address the challenge of design a feasible social-based mechanism to manage wireless mobile connectivity. In a previous work, we proposed a methodology to share connectivity experiences among mobile users inside on-line social networks [11]. The aim was explore peoples social circles to enhance their wireless connectivity experiences e.g., QoS metrics such as: throughput, latency and signal quality. In this paper, details of the mashups, between wireless connectivity context data and location-based social media, are provided. We report how this data is handled using complex networks metrics e.g., vertex's strength and centrality degree, to identify high density handover areas, define the mobile users' reputation and to reveal the networks' coverage. Real experiments showed that collaboration can improve QoS metrics from ∼18 to ∼30% if compared to just use a mobility predictor or a modern operational system, respectively. The discussion unfolds with focus on the collaboration's efficiency as function of time, number of users, discovered area size and mobility patterns.
Roberto Rigolin Ferreira Lopes, Azzedine Boukerche, Bert-Jan van Beijnum, Edson dos Santos Moreira
WCNC1
2011 Towards a feasible social-based methodology to manage wireless connectivity context data
abstract
Wireless connectivity context data is composed by date, time, geographical localization, and QoS metrics, to cite the most common. These data are employed, in a particular way, by fundamental techniques for context-aware connectivity management, e.g. mobility predictors, handoff mechanisms and mobility management. For instance, mobility and QoS predictors use, as input, previous georeferenced network context data. Normally, context data are available in hardly updated databases with considerable size. In this paper, we propose a social-based methodology to allow mobile users collaborate to discover wireless connectivity islands. The methodology is composed by methods to gather, combine, summarize and share context data inside the users' social circles. We, also, designed a schema to mashup context data with location-based social media. It is result of a prototyping effort and we focus the discussion on its feasibility and limitations in terms of storage size, power consumption and QoS metrics.
Roberto Rigolin Ferreira Lopes, Bert-Jan van Beijnum, Edson dos Santos Moreira
WiMob1
2007 QoS Proxy Architecture for Real Time RPC with Traffic Prediction
abstract
Currently, there are many research works focused at the creation of architectures that support QoS for real time multimedia applications guarantees. However, those architectures do not support the traffic of RT-RPCs whose requirements (i.e. priority and deadline) are harder than those of multimedia applications. The aim of this work is to propose an architecture of QoS proxy for RT-RPCs that uses Box-Jenkins time series models in order to predict future traffic characteristics of RT-RPCs that pass through the proxy, allowing the anticipated allocation of the necessary resources to attend the predicted demand and the choice of policies aimed at the adaptation of the proxy to the states of its network environment.
Pedro Northon Nobile, Roberto Rigolin Ferreira Lopes, Célio Estevan Morón, Luís Carlos Trevelin
DS-RT2