VLDB 2026 Research / reviewers in the wild / expert
Cristina Alcaraz
dblp:83/4732
· DBLP profile ↗
53ranked-venue papers
26as first author
13since 2021 · last 2026
0000-0003-0545-3191ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 14 first-author · 9 since 2021Systems, architecture and hardware · 6 · 5 first-author · 3 since 2021Computer networks · 6 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive Digital Twin: Protection, deception, and testingabstract• Adaptable cybersecurity capabilities driven by an adaptive digital twin • Adaptive digital twin for protection, deception, and testing • Characterization of an adaptive digital twin, capable of providing cybersecurity capabilities, such as protection, deception, and testing, in a safe and reliable manner. A Digital Twin (DT) is a cutting-edge technology that has gained relevance in recent years, demonstrating huge potential for the simulation of processes and the provision of valuable insights to improve and optimise systems. Leveraging a high degree of fidelity in replicating real-world processes, DTs are being explored for advanced applications such as deception and proactive protection of critical infrastructures. However, this same advantage also raises concerns with respect to a system’s exposure, as the detailed digital representation may introduce new cybersecurity risks. With the aim of assisting the growth of this technology, this paper presents an adaptive DT solution that facilitates the configuration of particular components of the digital system, tailoring different application scenarios specifically for protection, deception, and testing purposes. Finally, the proposed architecture is tested under a specific IoT-oriented use case to validate, experiment, and extract conclusions of the proposed solution. Cristina Alcaraz, Hector Guzman, Javier López 0001 |
Future Gener. Comput. Syst. | 1 |
| 2026 | Advanced situational awareness and resilience for hyper-connected industrial scenarios
Cristina Alcaraz, Fabio Martinelli, Panagiotis Bountakas |
Future Gener. Comput. Syst. | 1 |
| 2026 | Moderation is the Best Policy: Dynamic Defense Against Gradient-Based Data Reconstruction Attacks in Federated LearningabstractFederated learning (FL) is a privacy-preserving distributed machine learning framework. However, recent studies have shown that implementing gradient-based data reconstruction attacks (DRA) can still lead to the leakage of user privacy through frequently uploaded model parameters in FL. Existing works leverage differential privacy (DP) to prevent privacy leakage, but the lack of effective scheduling of the privacy budget results in significant accuracy loss in the trained models. In this paper, we propose a novel dynamic privacy preserving federated learning framework, named NDPP-FL, capable of delivering robust defenses against DRA while significantly mitigating performance loss. Our key insight is to regard the privacy budget as a non-replenishable resource and dynamically schedule it based on privacy leakage risks to provide self-adaptive privacy protection for clients across varying communication rounds. Specifically, based on the amount of information between the local dataset and the transmitted parameters, we first design a parameter channel information leakage model. Then, during each update iteration, we introduce saliency perturbations based on the Hessian matrix to enhance defensive capabilities. Meanwhile, to improve the performance of NDPP-FL, sample-adaptive clipping and decaying noise perturbations are adopted in the construction. Furthermore, extensive experiments demonstrate that our framework performs excellently in terms of model accuracy and resilience against DRA. Qinyang Miao, Wen Sun 0004, Dan Zhu 0001, Jinku Li, Yajin Zhou, Cristina Alcaraz |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Trusted Platform and Privacy Management in Cyber Physical Systems: The DUCA Framework
Antonio Muñoz 0001, Javier López 0001, Cristina Alcaraz, Fabio Martinelli |
DBSec | 3 |
| 2025 | Digital Twin for Adaptive Adversary Emulation in IIoT Control Networks
Javier Parada, Cristina Alcaraz, Javier López 0001, Juan Caubet, Rodrigo Roman |
ESORICS (3) | 2 |
| 2025 | Blockchain-Based Multi-Signature System for Critical Scenarios
Cristina Alcaraz, Davide Ferraris, Hector Guzman, Javier López 0001 |
SECRYPT | 1 |
| 2024 | SYNAPSE - An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSEabstractIn an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries. Panagiotis Bountakas, Konstantinos Fysarakis, Thomas Kyriakakis, Panagiotis Karafotis, Aristeidis Sotiropoulos, Maria Tasouli, Cristina Alcaraz, George Alexandris, Vassiliki Andronikou, Tzortzia Koutsouri, Romarick Yatagha, George Spanoudakis, Sotiris Ioannidis, Fabio Martinelli, Oleg Illiashenko |
ARES | 7 |
| 2024 | Safeguarding Industry 5.0 Ecosystems Through Digital Twins
Cristina Alcaraz |
ICISSP | 1 |
| 2023 | Cybersecurity in the digital world
Lorena González-Manzano, Marta Beltrán, José María de Fuentes, Gianluca Dini, Cristina Alcaraz |
Future Gener. Comput. Syst. | 5 |
| 2023 | Editorial CFP: IEEE Transactions on Industrial Informatics - Special Section on Digital Twin for Industrial Internet of ThingsabstractThe papers in this special section focus on digital twins for the Industrial Internet of Things. Yan Zhang 0002, Wen Sun 0004, Cristina Alcaraz |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | CPSIoTSec '22: 4th Workshop on CPS & IoT Security and PrivacyabstractThere is a rapidly growing interest in the security of cyber-physical systems (CPS) and internet-of-things (IoT) in industry, government and academia. This interest is also reflected in this workshop that from 2019 has been part of the ACM Conference on Computer and Communications Security, which originally hosted two workshops: One on CPS security and privacy (running 5 times in the past) and one on IoT security and privacy (running 2 times in the past). Due to the close connection of the two topics, the Steering Committees of the two workshops decided in 2020 to merge towards delivering a world-class event on CPS&IoT security and privacy. CPSIoTSec'22 corresponds to the fourth edition of this merger. Earlence Fernandes, Cristina Alcaraz |
CCS | 2 |
| 2022 | Collaborative Anomaly Detection System for Charging Stations
Jesus Cumplido, Cristina Alcaraz, Javier López 0001 |
ESORICS (2) | 2 |
| 2021 | Stakeholder perspectives and requirements on cybersecurity in EuropeabstractThis article presents an overview and analysis of the key cybersecurity problems, challenges and requirements to be addressed in the future, which we derived through 63 interviews with European stakeholders from security-critical sectors including Open Banking, Supply Chain, Privacy-preserving Identity Management, Security Incident Reporting, Maritime Transport, Medical Data Exchange, and Smart Cities. We show that common problems, challenges and requirements across these sectors exist in relation to building trust, implementing privacy and identity management including secure and useable authentication, building resilient systems, standardisation and certification, achieving security and privacy by design, secure and privacy-compliant data and information sharing, and government regulations. Our results also indicate cybersecurity trends and allow to derive directions for future research and innovation activities that will be of high importance for Europe. Simone Fischer-Hübner, Cristina Alcaraz, Afonso Ferreira, Carmen Fernández Gago, Javier López 0001, Evangelos P. Markatos, Lejla Islami, Mahdi Akil |
J. Inf. Secur. Appl. | 2 |
| 2020 | Game Theory-Based Approach for Defense Against APTs
Juan E. Rubio, Cristina Alcaraz, Javier López 0001 |
ACNS (2) | 2 |
| 2020 | Distributed Detection of APTs: Consensus vs. Clustering
Juan E. Rubio, Cristina Alcaraz, Ruben Rios, Rodrigo Roman, Javier López 0001 |
ESORICS (1) | 2 |
| 2020 | Blockchain-assisted access for federated Smart Grid domains: Coupling and featuresabstractIndustry 4.0 technological expansion and the multiple accesses to the diverse Smart Grid domains (power networks, control systems, market, customer premises) entail the need to provide efficient interconnection mechanisms with connection from anywhere, at any time and in anyhow. However, this type of requirement should not only consist in imposing interoperability solutions between entities and domains, but also in searching the way to justify and trace connections (how, when, where, who) for future governance or auditing actions. This paper, therefore, presents a three layer-based interconnection architecture and several interconnection strategies, all of them adapting the traditional policy decision and enforcement approaches together with the blockchain technology to manage reliable and secure connections among entities, processes and critical resources. With this architecture in mind, the paper also analyzes the coupling level of the blockchain technology, and explores which interconnection strategy is more suitable for Smart Grid domains and their control systems. Cristina Alcaraz, Juan E. Rubio, Javier López 0001 |
J. Parallel Distributed Comput. | 1 |
| 2020 | Guest Editorial: Special Section on Security and Privacy in Industry 4.0abstractThe papers in this special section focuses on security and privacy in industry. Industries, governments, and scientific communities are increasingly drawing special attention to competitive advantages that Industry 4.0 can bring to business sustainability and economy of a country. The tendency to couple information technologies (ITs) with the existing operational technologies (OTs) adds new opportunities to improve and optimize operational processes, products, and services in which multiple stakeholders (e.g., end-users) can interact with the new industrial ecosystems to speed up and customize processes. In this sense, Industry 4.0 constitutes a relevant investment source composed of a complex technological showcase in which multiple connections and accesses can arise, seriously impacting on the good performance of the different production and distribution chains associated with smart factories and manufacturing, smart grid systems, smart transportation, or smart health environments. Cristina Alcaraz, Yan Zhang 0002, Alvaro A. Cárdenas, Liehuang Zhu |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | SealedGRID: A Secure Interconnection of Technologies for Smart Grid Applications
Aristeidis Farao, Juan E. Rubio, Cristina Alcaraz, Christoforos Ntantogian, Christos Xenakis, Javier López 0001 |
CRITIS | 3 |
| 2019 | Enhancing Security and Dependability of Industrial Networks with Opinion Dynamics
Juan E. Rubio, Mark Manulis, Cristina Alcaraz, Javier López 0001 |
ESORICS (2) | 3 |
| 2019 | Current cyber-defense trends in industrial control systems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001 |
Comput. Secur. | 2 |
| 2019 | Guest Editorial Special Issue on Secure Embedded IoT Devices for Resilient Critical InfrastructuresabstractThe Internet of Things (IoT) creates new technological opportunities for a wide range of systems, such as industrial control systems, smart power grids, vehicular networks (VNs) and intelligent transportation systems, body area networks and healthcare monitoring and control systems and smart homes. At the same time, IoT also increases the threat surface for potential adversaries targeting critical interconnected systems that may depend on embedded IoT systems, such as supervisory control and data acquisition (SCADA) systems. At this point, attackers could take advantage from the incorporation of the paradigm to exploit new security gaps, probably caused by unforeseen interoperability and adaptability problems. Indeed, the deployment of Internet-enabled embedded devices that are distributed over major critical domains may create indirect and nonobvious interconnections with the underlying critical infrastructures (CIs). There is a need to further explore the security issues related to IoT technologies and to assure the resilience of CIs against advanced IoT-enabled attacks. The focus of this special issue is therefore to provide readers with the latest advances in securing the interaction between embedded IoT devices and CIs in order to increase their resilience to advanced IoT-enabled threats. Cristina Alcaraz, Mike Burmester, Jorge Cuéllar, Xinyi Huang 0001, Panayiotis Kotzanikolaou, Mihalis Psarakis |
IEEE Internet Things J. | 1 |
| 2019 | Tracking APTs in industrial ecosystems: A proof of conceptabstractIn recent years, Advanced Persistent Threats (APTs) have become a major issue for critical infrastructures that are increasingly integrating modern IT technologies. This requires the development of advanced cyber-security services that can holistically detect and trace these attacks, beyond traditional solutions. In this sense, Opinion Dynamics has been proven as an effective solution, as they can locate the most affected areas within the industrial network. With this information, it is possible to put in place accurate response techniques to limit the impact of attacks on the infrastructure. In this paper, we analyze the applicability of Opinion Dynamics to trace an APT throughout its entire life cycle, by correlating different anomalies over time and accounting for the persistence of threats and the criticality of resources. Moreover, we run various experiments with this novel technique over a testbed that models a real control system, thereby assessing its effectiveness in an actual industrial scenario. Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002 |
J. Comput. Secur. | 3 |
| 2018 | Tracking Advanced Persistent Threats in Critical Infrastructures Through Opinion Dynamics
Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002 |
ESORICS (1) | 3 |
| 2018 | Security and privacy in cloud-assisted cyber-physical systems
Cristina Alcaraz, Xinyi Huang 0001, Erich Rome |
Comput. Networks | 1 |
| 2018 | A Resilient Architecture for the Smart GridabstractThe smart grid offers many benefits due to the bidirectional communication between the users and the utility company, which makes it possible to perform a fine-grain consumption metering. This can be used for demand response purposes with the generation and delivery of electricity in real time. It is essential to rapidly anticipate high peaks of demand or potential attacks, so as to avoid power outages and denial of service, while effectively supplying consumption areas. In this paper, we propose a novel architecture where cloud computing resources are leveraged (and tested in practice) to enable, on the one hand, the consumption prediction through time-series forecasting, as well as load balancing to uniformly distribute the demand over a set of available generators. On the other hand, it also allows the detection of connectivity losses and intrusions within the control network by using controllability concepts. Javier López 0001, Juan E. Rubio, Cristina Alcaraz |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | Preventing Advanced Persistent Threats in Complex Control Networks
Juan E. Rubio, Cristina Alcaraz, Javier López 0001 |
ESORICS (2) | 2 |
| 2017 | Analysis of Intrusion Detection Systems in Industrial Ecosystems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001 |
SECRYPT | 2 |
| 2017 | Resilient interconnection in cyber-physical control systems
Cristina Alcaraz, Javier López 0001, Kim-Kwang Raymond Choo |
Comput. Secur. | 1 |
| 2017 | Recommender system for privacy-preserving solutions in smart metering
Juan E. Rubio, Cristina Alcaraz, Javier López 0001 |
Pervasive Mob. Comput. | 2 |
| 2016 | Selecting Privacy Solutions to Prioritise Control in Smart Metering Systems
Juan E. Rubio, Cristina Alcaraz, Javier López 0001 |
CRITIS | 2 |
| 2016 | Safeguarding Structural Controllability in Cyber-Physical Control Systems
Cristina Alcaraz, Javier López 0001 |
ESORICS (2) | 1 |
| 2016 | Dynamic Restoration in Interconnected RBAC-based Cyber-physical Control Systems
Cristina Alcaraz, Javier López 0001, Kim-Kwang Raymond Choo |
SECRYPT | 1 |
| 2016 | Policy enforcement system for secure interoperable control in distributed Smart Grid systems
Cristina Alcaraz, Javier López 0001, Stephen D. Wolthusen |
J. Netw. Comput. Appl. | 1 |
| 2015 | A three-stage analysis of IDS for critical infrastructures
Lorena Cazorla, Cristina Alcaraz, Javier López 0001 |
Comput. Secur. | 2 |
| 2014 | Context-Awareness Using Anomaly-Based Detectors for Smart Grid Domains
Cristina Alcaraz, Lorena Cazorla, Gerardo Fernandez |
CRiSIS | 1 |
| 2014 | WASAM: A dynamic wide-area situational awareness model for critical domains in Smart Grids
Cristina Alcaraz, Javier López 0001 |
Future Gener. Comput. Syst. | 1 |
| 2013 | Structural Controllability of Networks for Non-interactive Adversarial Vertex Removal
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen |
CRITIS | 1 |
| 2013 | Towards Automatic Critical Infrastructure Protection through Machine Learning
Lorena Cazorla, Cristina Alcaraz, Javier López 0001 |
CRITIS | 2 |
| 2013 | Multi-round Attacks on Structural Controllability Properties for Non-complete Random Graphs
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen |
ISC | 1 |
| 2013 | Security of industrial sensor network-based remote substations in the context of the Internet of Things
Cristina Alcaraz, Rodrigo Roman, Pablo Najera, Javier López 0001 |
Ad Hoc Networks | 1 |
| 2013 | Smart control of operational threats in control substations
Javier López 0001, Cristina Alcaraz, Rodrigo Roman |
Comput. Secur. | 2 |
| 2012 | PDR: A Prevention, Detection and Response Mechanism for Anomalies in Energy Control Systems
Cristina Alcaraz, Meltem Sönmez Turan |
CRITIS | 1 |
| 2012 | Smart Grid Privacy: Issues and SolutionsabstractMigration to an electronically controlled electrical grid to transmit, distribute, and deliver power to consumers has helped enhance the reliability and efficiency of conventional electricity systems. At the same time, this digitally enabled technology called the Smart Grid has brought new challenges to businesses and consumers alike. A key component of such a grid is the smart-metering technology, which is used to collect energy consumption data from homes and transmitting it back to power distributors. A crucial concern is the privacy related to the collection and use of energy consumption data. We present an analysis of Smart Grid privacy issues and discuss recently proposed solutions that can protect the privacy of Smart Grid users. Farhan Siddiqui, Sherali Zeadally, Cristina Alcaraz, Samara Galvao |
ICCCN | 3 |
| 2012 | Addressing Situational Awareness in Critical Domains of a Smart Grid
Cristina Alcaraz, Javier López 0001 |
NSS | 1 |
| 2012 | Selecting key management schemes for WSN applications
Cristina Alcaraz, Javier López 0001, Rodrigo Roman, Hsiao-Hwa Chen |
Comput. Secur. | 1 |
| 2011 | Managing Incidents in Smart Grids à la CloudabstractOver the last decade, the Cloud Computing paradigm has emerged as a panacea for many problems in traditional IT infrastructures. Much has been said about the potential of Cloud Computing in the context of the Smart Grid, but unfortunately it is still relegated to a second layer when it comes to critical systems. Although the advantages of outsourcing these kinds of applications to the cloud is clear, data confidentiality and operational privacy stand as mayor drawbacks. In this paper, we describe some security mechanisms, and specifically, some cryptographic schemes, that will help in a better integration of Smart Grids and Clouds. We propose the use of Virtual SCADA in the Cloud (VS-Cloud) as a means to improve reliability and efficiency whilst maintaining the same protection level as in traditional SCADA architectures. Cristina Alcaraz, Isaac Agudo, David Nuñez 0001, Javier López 0001 |
CloudCom | 1 |
| 2011 | Secure SCADA framework for the protection of energy control systemsabstractAbstract Energy distribution systems are becoming increasingly widespread in today's society. One of the elements that are used to monitor and control these systems are SCADA (Supervisory Control and Data Acquisition) systems. In particular, these control systems and their complexities, together with the emerging use of the Internet and wireless technologies, bring new challenges that must be carefully considered. Examples of such challenges are the particular benefits of the integration of those new technologies, and also the effects they may have on the overall SCADA security. The main task of this paper is to provide a framework that shows how the integration of different state‐of‐the‐art technologies in an energy control system, such as wireless sensor networks, mobilead hocnetworks, and the Internet, can bring some interesting benefits, such as status management and anomaly prevention, while maintaining the security of the whole system. Copyright © 2010 John Wiley & Sons, Ltd. Cristina Alcaraz, Javier López 0001, Jianying Zhou 0001, Rodrigo Roman |
Concurr. Comput. Pract. Exp. | 1 |
| 2010 | Early Warning System for Cascading Effect Control in Energy Control Systems
Cristina Alcaraz, Angel Balastegui, Javier López 0001 |
CRITIS | 1 |
| 2010 | A Security Analysis for Wireless Sensor Mesh Networks in Highly Critical SystemsabstractNowadays, critical control systems are a fundamental component contributing to the overall performance of critical infrastructures in our society, most of which belong to the industrial sector. These complex systems include in their design different types of information and communication technology systems, such as wireless (mesh) sensor networks, to carry out control processes in real time. This fact has meant that several communication standards, such as Zigbee PRO, WirelessHART, and ISA100.11a, have been specified to ensure coexistence, reliability, and security in their communications. The main purpose of this paper has been to review these three standards and analyze their security. We have identified a set of threats and potential attacks in their routing protocols, and we consequently provide recommendations and countermeasures to help Industry protect its infrastructures. Cristina Alcaraz, Javier López 0001 |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2009 | Adaptive Dispatching of Incidences Based on Reputation for SCADA Systems
Cristina Alcaraz, Isaac Agudo, Carmen Fernández Gago, Rodrigo Roman, Gerardo Fernandez, Javier López 0001 |
TrustBus | 1 |
| 2007 | The role of Wireless Sensor Networks in the area of Critical Information Infrastructure Protection
Rodrigo Roman, Cristina Alcaraz, Javier López 0001 |
Inf. Secur. Tech. Rep. | 2 |
| 2007 | A Survey of Cryptographic Primitives and Implementations for Hardware-Constrained Sensor Network Nodes
Rodrigo Roman, Cristina Alcaraz, Javier López 0001 |
Mob. Networks Appl. | 2 |
| 2006 | Applying Key Infrastructures for Sensor Networks in CIP/CIIP Scenarios
Cristina Alcaraz, Rodrigo Roman |
CRITIS | 1 |