Cristina Alcaraz

dblp:83/4732 · DBLP profile ↗
← Back
53ranked-venue papers
26as first author
13since 2021 · last 2026
0000-0003-0545-3191ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 14 first-author · 9 since 2021Systems, architecture and hardware · 6 · 5 first-author · 3 since 2021Computer networks · 6 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
YearPublicationVenuePosition
2026 Adaptive Digital Twin: Protection, deception, and testing
abstract
• Adaptable cybersecurity capabilities driven by an adaptive digital twin • Adaptive digital twin for protection, deception, and testing • Characterization of an adaptive digital twin, capable of providing cybersecurity capabilities, such as protection, deception, and testing, in a safe and reliable manner. A Digital Twin (DT) is a cutting-edge technology that has gained relevance in recent years, demonstrating huge potential for the simulation of processes and the provision of valuable insights to improve and optimise systems. Leveraging a high degree of fidelity in replicating real-world processes, DTs are being explored for advanced applications such as deception and proactive protection of critical infrastructures. However, this same advantage also raises concerns with respect to a system’s exposure, as the detailed digital representation may introduce new cybersecurity risks. With the aim of assisting the growth of this technology, this paper presents an adaptive DT solution that facilitates the configuration of particular components of the digital system, tailoring different application scenarios specifically for protection, deception, and testing purposes. Finally, the proposed architecture is tested under a specific IoT-oriented use case to validate, experiment, and extract conclusions of the proposed solution.
Cristina Alcaraz, Hector Guzman, Javier López 0001
Future Gener. Comput. Syst.1
2026 Advanced situational awareness and resilience for hyper-connected industrial scenarios
Cristina Alcaraz, Fabio Martinelli, Panagiotis Bountakas
Future Gener. Comput. Syst.1
2026 Moderation is the Best Policy: Dynamic Defense Against Gradient-Based Data Reconstruction Attacks in Federated Learning
abstract
Federated learning (FL) is a privacy-preserving distributed machine learning framework. However, recent studies have shown that implementing gradient-based data reconstruction attacks (DRA) can still lead to the leakage of user privacy through frequently uploaded model parameters in FL. Existing works leverage differential privacy (DP) to prevent privacy leakage, but the lack of effective scheduling of the privacy budget results in significant accuracy loss in the trained models. In this paper, we propose a novel dynamic privacy preserving federated learning framework, named NDPP-FL, capable of delivering robust defenses against DRA while significantly mitigating performance loss. Our key insight is to regard the privacy budget as a non-replenishable resource and dynamically schedule it based on privacy leakage risks to provide self-adaptive privacy protection for clients across varying communication rounds. Specifically, based on the amount of information between the local dataset and the transmitted parameters, we first design a parameter channel information leakage model. Then, during each update iteration, we introduce saliency perturbations based on the Hessian matrix to enhance defensive capabilities. Meanwhile, to improve the performance of NDPP-FL, sample-adaptive clipping and decaying noise perturbations are adopted in the construction. Furthermore, extensive experiments demonstrate that our framework performs excellently in terms of model accuracy and resilience against DRA.
Qinyang Miao, Wen Sun 0004, Dan Zhu 0001, Jinku Li, Yajin Zhou, Cristina Alcaraz
IEEE Trans. Dependable Secur. Comput.6
2025 Trusted Platform and Privacy Management in Cyber Physical Systems: The DUCA Framework
Antonio Muñoz 0001, Javier López 0001, Cristina Alcaraz, Fabio Martinelli
DBSec3
2025 Digital Twin for Adaptive Adversary Emulation in IIoT Control Networks
Javier Parada, Cristina Alcaraz, Javier López 0001, Juan Caubet, Rodrigo Roman
ESORICS (3)2
2025 Blockchain-Based Multi-Signature System for Critical Scenarios
Cristina Alcaraz, Davide Ferraris, Hector Guzman, Javier López 0001
SECRYPT1
2024 SYNAPSE - An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSE
abstract
In an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries.
Panagiotis Bountakas, Konstantinos Fysarakis, Thomas Kyriakakis, Panagiotis Karafotis, Aristeidis Sotiropoulos, Maria Tasouli, Cristina Alcaraz, George Alexandris, Vassiliki Andronikou, Tzortzia Koutsouri, Romarick Yatagha, George Spanoudakis, Sotiris Ioannidis, Fabio Martinelli, Oleg Illiashenko
ARES7
2024 Safeguarding Industry 5.0 Ecosystems Through Digital Twins
Cristina Alcaraz
ICISSP1
2023 Cybersecurity in the digital world
Lorena González-Manzano, Marta Beltrán, José María de Fuentes, Gianluca Dini, Cristina Alcaraz
Future Gener. Comput. Syst.5
2023 Editorial CFP: IEEE Transactions on Industrial Informatics - Special Section on Digital Twin for Industrial Internet of Things
abstract
The papers in this special section focus on digital twins for the Industrial Internet of Things.
Yan Zhang 0002, Wen Sun 0004, Cristina Alcaraz
IEEE Trans. Ind. Informatics3
2022 CPSIoTSec '22: 4th Workshop on CPS & IoT Security and Privacy
abstract
There is a rapidly growing interest in the security of cyber-physical systems (CPS) and internet-of-things (IoT) in industry, government and academia. This interest is also reflected in this workshop that from 2019 has been part of the ACM Conference on Computer and Communications Security, which originally hosted two workshops: One on CPS security and privacy (running 5 times in the past) and one on IoT security and privacy (running 2 times in the past). Due to the close connection of the two topics, the Steering Committees of the two workshops decided in 2020 to merge towards delivering a world-class event on CPS&IoT security and privacy. CPSIoTSec'22 corresponds to the fourth edition of this merger.
Earlence Fernandes, Cristina Alcaraz
CCS2
2022 Collaborative Anomaly Detection System for Charging Stations
Jesus Cumplido, Cristina Alcaraz, Javier López 0001
ESORICS (2)2
2021 Stakeholder perspectives and requirements on cybersecurity in Europe
abstract
This article presents an overview and analysis of the key cybersecurity problems, challenges and requirements to be addressed in the future, which we derived through 63 interviews with European stakeholders from security-critical sectors including Open Banking, Supply Chain, Privacy-preserving Identity Management, Security Incident Reporting, Maritime Transport, Medical Data Exchange, and Smart Cities. We show that common problems, challenges and requirements across these sectors exist in relation to building trust, implementing privacy and identity management including secure and useable authentication, building resilient systems, standardisation and certification, achieving security and privacy by design, secure and privacy-compliant data and information sharing, and government regulations. Our results also indicate cybersecurity trends and allow to derive directions for future research and innovation activities that will be of high importance for Europe.
Simone Fischer-Hübner, Cristina Alcaraz, Afonso Ferreira, Carmen Fernández Gago, Javier López 0001, Evangelos P. Markatos, Lejla Islami, Mahdi Akil
J. Inf. Secur. Appl.2
2020 Game Theory-Based Approach for Defense Against APTs
Juan E. Rubio, Cristina Alcaraz, Javier López 0001
ACNS (2)2
2020 Distributed Detection of APTs: Consensus vs. Clustering
Juan E. Rubio, Cristina Alcaraz, Ruben Rios, Rodrigo Roman, Javier López 0001
ESORICS (1)2
2020 Blockchain-assisted access for federated Smart Grid domains: Coupling and features
abstract
Industry 4.0 technological expansion and the multiple accesses to the diverse Smart Grid domains (power networks, control systems, market, customer premises) entail the need to provide efficient interconnection mechanisms with connection from anywhere, at any time and in anyhow. However, this type of requirement should not only consist in imposing interoperability solutions between entities and domains, but also in searching the way to justify and trace connections (how, when, where, who) for future governance or auditing actions. This paper, therefore, presents a three layer-based interconnection architecture and several interconnection strategies, all of them adapting the traditional policy decision and enforcement approaches together with the blockchain technology to manage reliable and secure connections among entities, processes and critical resources. With this architecture in mind, the paper also analyzes the coupling level of the blockchain technology, and explores which interconnection strategy is more suitable for Smart Grid domains and their control systems.
Cristina Alcaraz, Juan E. Rubio, Javier López 0001
J. Parallel Distributed Comput.1
2020 Guest Editorial: Special Section on Security and Privacy in Industry 4.0
abstract
The papers in this special section focuses on security and privacy in industry. Industries, governments, and scientific communities are increasingly drawing special attention to competitive advantages that Industry 4.0 can bring to business sustainability and economy of a country. The tendency to couple information technologies (ITs) with the existing operational technologies (OTs) adds new opportunities to improve and optimize operational processes, products, and services in which multiple stakeholders (e.g., end-users) can interact with the new industrial ecosystems to speed up and customize processes. In this sense, Industry 4.0 constitutes a relevant investment source composed of a complex technological showcase in which multiple connections and accesses can arise, seriously impacting on the good performance of the different production and distribution chains associated with smart factories and manufacturing, smart grid systems, smart transportation, or smart health environments.
Cristina Alcaraz, Yan Zhang 0002, Alvaro A. Cárdenas, Liehuang Zhu
IEEE Trans. Ind. Informatics1
2019 SealedGRID: A Secure Interconnection of Technologies for Smart Grid Applications
Aristeidis Farao, Juan E. Rubio, Cristina Alcaraz, Christoforos Ntantogian, Christos Xenakis, Javier López 0001
CRITIS3
2019 Enhancing Security and Dependability of Industrial Networks with Opinion Dynamics
Juan E. Rubio, Mark Manulis, Cristina Alcaraz, Javier López 0001
ESORICS (2)3
2019 Current cyber-defense trends in industrial control systems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001
Comput. Secur.2
2019 Guest Editorial Special Issue on Secure Embedded IoT Devices for Resilient Critical Infrastructures
abstract
The Internet of Things (IoT) creates new technological opportunities for a wide range of systems, such as industrial control systems, smart power grids, vehicular networks (VNs) and intelligent transportation systems, body area networks and healthcare monitoring and control systems and smart homes. At the same time, IoT also increases the threat surface for potential adversaries targeting critical interconnected systems that may depend on embedded IoT systems, such as supervisory control and data acquisition (SCADA) systems. At this point, attackers could take advantage from the incorporation of the paradigm to exploit new security gaps, probably caused by unforeseen interoperability and adaptability problems. Indeed, the deployment of Internet-enabled embedded devices that are distributed over major critical domains may create indirect and nonobvious interconnections with the underlying critical infrastructures (CIs). There is a need to further explore the security issues related to IoT technologies and to assure the resilience of CIs against advanced IoT-enabled attacks. The focus of this special issue is therefore to provide readers with the latest advances in securing the interaction between embedded IoT devices and CIs in order to increase their resilience to advanced IoT-enabled threats.
Cristina Alcaraz, Mike Burmester, Jorge Cuéllar, Xinyi Huang 0001, Panayiotis Kotzanikolaou, Mihalis Psarakis
IEEE Internet Things J.1
2019 Tracking APTs in industrial ecosystems: A proof of concept
abstract
In recent years, Advanced Persistent Threats (APTs) have become a major issue for critical infrastructures that are increasingly integrating modern IT technologies. This requires the development of advanced cyber-security services that can holistically detect and trace these attacks, beyond traditional solutions. In this sense, Opinion Dynamics has been proven as an effective solution, as they can locate the most affected areas within the industrial network. With this information, it is possible to put in place accurate response techniques to limit the impact of attacks on the infrastructure. In this paper, we analyze the applicability of Opinion Dynamics to trace an APT throughout its entire life cycle, by correlating different anomalies over time and accounting for the persistence of threats and the criticality of resources. Moreover, we run various experiments with this novel technique over a testbed that models a real control system, thereby assessing its effectiveness in an actual industrial scenario.
Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002
J. Comput. Secur.3
2018 Tracking Advanced Persistent Threats in Critical Infrastructures Through Opinion Dynamics
Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002
ESORICS (1)3
2018 Security and privacy in cloud-assisted cyber-physical systems
Cristina Alcaraz, Xinyi Huang 0001, Erich Rome
Comput. Networks1
2018 A Resilient Architecture for the Smart Grid
abstract
The smart grid offers many benefits due to the bidirectional communication between the users and the utility company, which makes it possible to perform a fine-grain consumption metering. This can be used for demand response purposes with the generation and delivery of electricity in real time. It is essential to rapidly anticipate high peaks of demand or potential attacks, so as to avoid power outages and denial of service, while effectively supplying consumption areas. In this paper, we propose a novel architecture where cloud computing resources are leveraged (and tested in practice) to enable, on the one hand, the consumption prediction through time-series forecasting, as well as load balancing to uniformly distribute the demand over a set of available generators. On the other hand, it also allows the detection of connectivity losses and intrusions within the control network by using controllability concepts.
Javier López 0001, Juan E. Rubio, Cristina Alcaraz
IEEE Trans. Ind. Informatics3
2017 Preventing Advanced Persistent Threats in Complex Control Networks
Juan E. Rubio, Cristina Alcaraz, Javier López 0001
ESORICS (2)2
2017 Analysis of Intrusion Detection Systems in Industrial Ecosystems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001
SECRYPT2
2017 Resilient interconnection in cyber-physical control systems
Cristina Alcaraz, Javier López 0001, Kim-Kwang Raymond Choo
Comput. Secur.1
2017 Recommender system for privacy-preserving solutions in smart metering
Juan E. Rubio, Cristina Alcaraz, Javier López 0001
Pervasive Mob. Comput.2
2016 Selecting Privacy Solutions to Prioritise Control in Smart Metering Systems
Juan E. Rubio, Cristina Alcaraz, Javier López 0001
CRITIS2
2016 Safeguarding Structural Controllability in Cyber-Physical Control Systems
Cristina Alcaraz, Javier López 0001
ESORICS (2)1
2016 Dynamic Restoration in Interconnected RBAC-based Cyber-physical Control Systems
Cristina Alcaraz, Javier López 0001, Kim-Kwang Raymond Choo
SECRYPT1
2016 Policy enforcement system for secure interoperable control in distributed Smart Grid systems
Cristina Alcaraz, Javier López 0001, Stephen D. Wolthusen
J. Netw. Comput. Appl.1
2015 A three-stage analysis of IDS for critical infrastructures
Lorena Cazorla, Cristina Alcaraz, Javier López 0001
Comput. Secur.2
2014 Context-Awareness Using Anomaly-Based Detectors for Smart Grid Domains
Cristina Alcaraz, Lorena Cazorla, Gerardo Fernandez
CRiSIS1
2014 WASAM: A dynamic wide-area situational awareness model for critical domains in Smart Grids
Cristina Alcaraz, Javier López 0001
Future Gener. Comput. Syst.1
2013 Structural Controllability of Networks for Non-interactive Adversarial Vertex Removal
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen
CRITIS1
2013 Towards Automatic Critical Infrastructure Protection through Machine Learning
Lorena Cazorla, Cristina Alcaraz, Javier López 0001
CRITIS2
2013 Multi-round Attacks on Structural Controllability Properties for Non-complete Random Graphs
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen
ISC1
2013 Security of industrial sensor network-based remote substations in the context of the Internet of Things
Cristina Alcaraz, Rodrigo Roman, Pablo Najera, Javier López 0001
Ad Hoc Networks1
2013 Smart control of operational threats in control substations
Javier López 0001, Cristina Alcaraz, Rodrigo Roman
Comput. Secur.2
2012 PDR: A Prevention, Detection and Response Mechanism for Anomalies in Energy Control Systems
Cristina Alcaraz, Meltem Sönmez Turan
CRITIS1
2012 Smart Grid Privacy: Issues and Solutions
abstract
Migration to an electronically controlled electrical grid to transmit, distribute, and deliver power to consumers has helped enhance the reliability and efficiency of conventional electricity systems. At the same time, this digitally enabled technology called the Smart Grid has brought new challenges to businesses and consumers alike. A key component of such a grid is the smart-metering technology, which is used to collect energy consumption data from homes and transmitting it back to power distributors. A crucial concern is the privacy related to the collection and use of energy consumption data. We present an analysis of Smart Grid privacy issues and discuss recently proposed solutions that can protect the privacy of Smart Grid users.
Farhan Siddiqui, Sherali Zeadally, Cristina Alcaraz, Samara Galvao
ICCCN3
2012 Addressing Situational Awareness in Critical Domains of a Smart Grid
Cristina Alcaraz, Javier López 0001
NSS1
2012 Selecting key management schemes for WSN applications
Cristina Alcaraz, Javier López 0001, Rodrigo Roman, Hsiao-Hwa Chen
Comput. Secur.1
2011 Managing Incidents in Smart Grids à la Cloud
abstract
Over the last decade, the Cloud Computing paradigm has emerged as a panacea for many problems in traditional IT infrastructures. Much has been said about the potential of Cloud Computing in the context of the Smart Grid, but unfortunately it is still relegated to a second layer when it comes to critical systems. Although the advantages of outsourcing these kinds of applications to the cloud is clear, data confidentiality and operational privacy stand as mayor drawbacks. In this paper, we describe some security mechanisms, and specifically, some cryptographic schemes, that will help in a better integration of Smart Grids and Clouds. We propose the use of Virtual SCADA in the Cloud (VS-Cloud) as a means to improve reliability and efficiency whilst maintaining the same protection level as in traditional SCADA architectures.
Cristina Alcaraz, Isaac Agudo, David Nuñez 0001, Javier López 0001
CloudCom1
2011 Secure SCADA framework for the protection of energy control systems
abstract
Abstract Energy distribution systems are becoming increasingly widespread in today's society. One of the elements that are used to monitor and control these systems are SCADA (Supervisory Control and Data Acquisition) systems. In particular, these control systems and their complexities, together with the emerging use of the Internet and wireless technologies, bring new challenges that must be carefully considered. Examples of such challenges are the particular benefits of the integration of those new technologies, and also the effects they may have on the overall SCADA security. The main task of this paper is to provide a framework that shows how the integration of different state‐of‐the‐art technologies in an energy control system, such as wireless sensor networks, mobilead hocnetworks, and the Internet, can bring some interesting benefits, such as status management and anomaly prevention, while maintaining the security of the whole system. Copyright © 2010 John Wiley & Sons, Ltd.
Cristina Alcaraz, Javier López 0001, Jianying Zhou 0001, Rodrigo Roman
Concurr. Comput. Pract. Exp.1
2010 Early Warning System for Cascading Effect Control in Energy Control Systems
Cristina Alcaraz, Angel Balastegui, Javier López 0001
CRITIS1
2010 A Security Analysis for Wireless Sensor Mesh Networks in Highly Critical Systems
abstract
Nowadays, critical control systems are a fundamental component contributing to the overall performance of critical infrastructures in our society, most of which belong to the industrial sector. These complex systems include in their design different types of information and communication technology systems, such as wireless (mesh) sensor networks, to carry out control processes in real time. This fact has meant that several communication standards, such as Zigbee PRO, WirelessHART, and ISA100.11a, have been specified to ensure coexistence, reliability, and security in their communications. The main purpose of this paper has been to review these three standards and analyze their security. We have identified a set of threats and potential attacks in their routing protocols, and we consequently provide recommendations and countermeasures to help Industry protect its infrastructures.
Cristina Alcaraz, Javier López 0001
IEEE Trans. Syst. Man Cybern. Part C1
2009 Adaptive Dispatching of Incidences Based on Reputation for SCADA Systems
Cristina Alcaraz, Isaac Agudo, Carmen Fernández Gago, Rodrigo Roman, Gerardo Fernandez, Javier López 0001
TrustBus1
2007 The role of Wireless Sensor Networks in the area of Critical Information Infrastructure Protection
Rodrigo Roman, Cristina Alcaraz, Javier López 0001
Inf. Secur. Tech. Rep.2
2007 A Survey of Cryptographic Primitives and Implementations for Hardware-Constrained Sensor Network Nodes
Rodrigo Roman, Cristina Alcaraz, Javier López 0001
Mob. Networks Appl.2
2006 Applying Key Infrastructures for Sensor Networks in CIP/CIIP Scenarios
Cristina Alcaraz, Rodrigo Roman
CRITIS1