EDBT 2026 Demo / reviewers in the wild / expert
Carlos E. Rubio-Medrano
dblp:11/3908
· DBLP profile ↗
26ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0001-8931-6412ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 5 first-author · 12 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Capable and Secure Autonomous Computer-Use Agents (Student Abstract)abstractAutonomous computer-use agents (ACUAs) enable end-to-end computer operation with human-like capabilities, executing commands across applications and making independent decisions. However, their real-world effectiveness and security remain largely untested. A systematic evaluation of ACUAs from Anthropic, OpenAI, and open-source projects categorized them into full computer access and browser-based agents. Findings reveal substantial limitations, with success rates dropping as low as 28% in some cases. Additionally, a 100% rate of unauthorized software installation was observed in certain tasks. The agents also demonstrated susceptibility to prompt injection attacks. The impact of varied prompting strategies on performance was also examined. In response to these weaknesses, a new agent framework designed to address these limitations is proposed. This work bridges agentic AI, human-computer interaction (HCI), and security to address the observed limitations of ACUAs, prioritizing both capability and safety. Malak Mahdy, Carlos E. Rubio-Medrano |
AAAI | 2 |
| 2026 | HoneySat: A Network-based Satellite Honeypot Framework
Efrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes, Jacob Hopkins, Majid Garoosi, Elías Obreque, Carlos E. Rubio-Medrano, Ali Abbasi 0002 |
NDSS | 8 |
| 2026 | Towards Agentic AI for Access Control in Cyber-infrastructures: Exploring the Security and Human Factors: [BlueSky Paper]abstractAccess Control (AC) remains one of the fundamental paradigms of computer security due to its potential to mitigate serious threats by restricting access to sensitive resources within emerging technologies. However, despite decades of research, the life-cycle, i.e., specification, evaluation, and enforcement, of AC policies in modern cyber-infrastructures remains incomplete, inaccurate, and unverified, which largely decreases their effectiveness and efficiency to counteract emerging threats and vulnerabilities. Carlos E. Rubio-Medrano, Souradip Nath, Ananta Soneji, Jennifer Mondragon, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 1 |
| 2025 | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing InfrastructuresabstractResearch Computing Infrastructures (RCIs) inte-grate high-performance computing, advanced data storage solutions, and sophisticated network protocols, connecting people, data, and computing resources to facilitate scientific collaboration in today's data-driven world. Access control is essential in such highly collaborative environments to prevent resource misutilization, safeguard data integrity, and allocate resources effectively, thereby enabling secure and trusted in-teractions among different users. However, unlocking the full potential of RCIs for collaborative research through effective access control requires more than technological exploration-it demands a deep, human-centered understanding of the stakeholders who operate and utilize these systems. In this paper, we present the first qualitative study that explores the human dimensions of RCI interactions, drawing insights from 24 key stakeholders, including researchers and system administrators, across 12 research institutions to ex-amine the collaborative practices, challenges, and needs with a focus on access control. Our findings reveal operational complexities and project-specific, trust-based resource-sharing dynamics, highlighting tensions between security and usability. Based on these insights, we provide stakeholder-driven rec-ommendations and requirements for adaptive, user-centered access control for RCIs, laying the groundwork for advancing human-centered security practices in RCIs. Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doupé, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
SP | 6 |
| 2024 | Fly-ABAC: Attribute Based Access Control for the Navigation of Unmanned Aerial VehiclesabstractWith the increasing deployment of UAVs across more and more domains such as surveillance, agriculture monitoring, and commercial delivery, there is an increasing need for robust systems that respect both federal regulations and private property owners’ constraints. To address these concerns, this paper presents a novel application of Attribute-Based Access Control (ABAC) for the navigation of Unmanned Aerial Vehicles (UAVs) to ensure compliance with both federal and public property owner preferences. Our research demonstrates that an ABAC system we call Fly-ABAC can effectively manage complex property restrictions by modeling positive and negative attributes as well as exclusion zones. Through simulations, our system has shown the ability to generate paths that avoid unauthorized zones and comply with specified access requirements, ensuring a high level of precision and customization in property access control.By leveraging the granularity of ABAC, Fly-ABAC can accommodate diverse property preferences and is easy to adjust to different scenarios, making it suitable for a wide range of applications, including enforcing regulations for flying over government buildings, airports, emergency operations, and private properties. Our findings indicate that this system not only enhances security and compliance but also provides property owners with a powerful tool to enforce their access policies. The implications of this research extend to improving the safety and operational efficiency of UAVs in complex environments, paving the way for the broader adoption of UAV for both commercial and private uses. Wynter Japp, Victoria Lee, Sai Avinash Vagicherla, Carlos E. Rubio-Medrano |
IEEE Big Data | 4 |
| 2024 | Asserting Frame Properties
Yoonsik Cheon, Bozhen Liu, Carlos E. Rubio-Medrano |
ICSOFT | 3 |
| 2024 | SecureCheck: User-Centric and Geolocation-Aware Access Mediation Contracts for Sharing Private DataabstractData oversharing is a critical issue in today's technologically driven society. Numerous entities, i.e., corporations, governments, criminal groups, are collecting individuals' data. One potential cause is that current systems, such as verification systems, do not prioritize the minimization of exchanged data. To address this issue, we propose SecureCheck, a novel privacy-enhancing technology (PET) framework that prioritizes data minimization. We aim to ensure that individuals control technology and its access to themselves, and not technology controlling individuals or their data. To that end, our proposed framework is comprised of two components: a novel access control model, called access mediation contracts, that enables users to negotiate with third parties over what data is used in a verification event, and a novel recommendation system that recommends the access mediation contracts in situationally-aware manner using geolocation data. As a part of ongoing work, we are developing a privacy calculus model detailing the decision process for data exchange. Also, we are conducting an exploratory study to better identify how to resolve conflicts between data owners and verifiers. Finally, we are actively working towards VaxCheck, a prototype implementation of SecureCheck focused on vaccine verification systems, so we can assess its effectiveness and suitability for future deployments in practice. Jacob Hopkins, Carlos E. Rubio-Medrano |
SACMAT | 2 |
| 2024 | Circles of Trust: A Voice-Based Authorization Scheme for Securing IoT Smart HomesabstractSmart homes, powered by a plethora of Internet of Things (IoT) devices, such as smart thermostats, lights, and TVs, have gained immense popularity due to their simple voice command control, making them user-friendly for homeowners and their families. However, these voice commands can be potentially misused, especially by unauthorized individuals, like visitors or thieves, who may have not been previously authorized to manipulate security sensitive devices, e.g., smart locks. To address this issue, we propose a novel approach called Circles of Trust (CoT), rooted in a well-known namesake psychological concept which associates relationships to a specific degree of trust. This concept can be applied to an authorization framework, by linking relationships to an access level, e.g., homeowners and their spouses can be fully-trusted, whereas visitors and children may not. CoT can be further visualized as a multi-layered circle, where the most privileged user, e.g., a homeowner, is placed within the innermost layer, and therefore has access to every single device within a smart home via voice commands. Each subsequent layer has fewer access privileges than the previous, granting users in outer layers, like visitors, limited capabilities to manipulate devices. CoT aims to preserve the ease-of-access and convenience of smart home devices by integrating voice-based security policies, eliminating the need for graphical user interfaces (GUIs). The proposed CoT implementation includes three main components: the voice-to-text module, authorization engine, and IoT orchestrator. Following a prototype implementation, a user study and questionnaire will assess the user-friendliness and device convenience. Jennifer Mondragon, Gael Cruz, Dvijesh Shastri, Carlos E. Rubio-Medrano |
SACMAT | 4 |
| 2024 | Pairing Human and Artificial Intelligence: Enforcing Access Control Policies with LLMs and Formal Specifications
Carlos E. Rubio-Medrano, Akash Kotak, Wenlu Wang, Karsten Sohr |
SACMAT | 1 |
| 2024 | SoK: Security of Programmable Logic Controllers
Efrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi 0002, Alvaro A. Cárdenas |
USENIX Security Symposium | 3 |
| 2023 | Poster: No Fly-Zone: Drone Policies for Ensuring Safe Operations in Restricted AreasabstractAs the use of drones continues to proliferate across various industries, ensuring their safe and secure operation becomes increasingly important. This abstract explores the techniques and strategies employed for drone identification and communication, aiming to enhance safety, security, and compliance. The paper highlights the significance of reliable drone recognition methods and effective communication protocols between drones and relevant parties. Specifically, it emphasizes the need for drones to adapt to restrictions, follow protocols, and communicate information in designated zones. Furthermore, the abstract emphasizes the importance of strict adherence to no-fly rules, precise identification of restricted airspace, and the establishment of robust communication protocols to prevent violations in high-security areas. The findings emphasize the significance of these techniques in promoting a safe and secure drone ecosystem and provide valuable insights for policymakers, drone operators, and stakeholders involved in managing and regulating drone operations. Arturo Gonzalez, Amani Davidson, Carlos E. Rubio-Medrano |
MobiHoc | 3 |
| 2023 | No-Fly-Zone: Regulating Drone Fly-Overs Via Government and User-Controlled Authorization ZonesabstractUnmanned Aerial Systems (UAVs), a.k.a., drones, are becoming increasingly popular, as several companies are incorporating them into highly-convenient, last-mile delivery systems. Given this market, concerns with non-consensual surveillance and destruction of drones and private property have been raised. To address these concerns, this paper presents No-Fly-Zone, a solution that proposes developing a series of physical spaces, a.k.a., zones, that utilize Attribute-Based Access Control (ABAC) to allow users, e.g., homeowners, to define flight authorization for drones. With zones that highlight no-fly air-spaces, companies will be able to launch their drones with a lowered chance of human interference or liability, allowing for property owners to determine which level of privacy they wish to enforce. Moreover, using a map that incorporates zoning preferences, a drone path planning algorithm can safely designate a path for any commercial drone flight. No-Fly-Zone also provides a a user-friendly application for collecting and deploying zoning data to pathing algorithms with limited setbacks, thus encouraging the future integration of No-Fly-Zone with existing and future drone flight management systems. Abdullah Kamal, Jeremy Vidaurri, Carlos E. Rubio-Medrano |
MobiHoc | 3 |
| 2023 | SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented RealityabstractMobile Augmented Reality (MAR) is a portable, powerful, and suitable technology that integrates digital content, e.g., 3D virtual objects, into the physical world, which not only has been implemented for multiple intents such as shopping, entertainment, gaming, etc., but it is also expected to grow at a tremendous rate in the upcoming years. Unfortunately, the applications that implement MAR, hereby referred to as MAR-Apps, bear security issues, which have been imaged in worldwide incidents such as robberies, which has led authorities to ban MAR-Apps at specific locations. Existing problems with MAR-Apps can be classified into three categories: first, Space Invasion, which implies the intrusive modification through MAR of sensitive spaces, e.g., hospitals, memorials, etc. Second, Space Affectation, which involves the degradation of users' experience via interaction with undesirable MAR or malicious entities. Finally, MAR-Apps mishandling sensitive data leads to Privacy Leaks. Luis Claramunt, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 2 |
| 2022 | "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security PapersabstractThe academic computer security community has traditionally adopted peer review as an integral part of scientific publishing and dissemination, in a process that grows organically and nourishes itself by internal communications and intuitions, rather than repeatable experiments and investigations. Recently, key community members have shared a series of concerns regarding this process in public. To support or disprove some of these concerns, this paper presents the first qualitative study to examine the peer review process in the computer security field. Through semi-structured interviews (n=21) with Program Committee members, we systematically collect the reviewers’ insights on how papers are evaluated in top-tier security conferences and investigate their concerns regarding the current security peer review system. Based on the collected data, we identify several issues in the security review system: whereas some have been previously observed by the community (e.g., the randomness in reviewers’ decisions), others (e.g., reviewers have much more diverse and concrete opinions on the metrics of rejecting papers) have been observed for the first time in our study. Finally, through a series of recommendations, we aim to encourage the collaborative establishment of community norms that will significantly improve the security peer review process. Ananta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé |
SP | 3 |
| 2021 | Poster: Preventing Spatial and Privacy Attacks in Mobile Augmented Reality TechnologiesabstractThe growing popularity of applications featuring Mobile Augmented Reality (MAR) raises serious concerns regarding the use of such a game-changing technology inside sensitive physical spaces, e.g., memorials, hospitals, museums, etc., such that the safety and privacy of users is preserved. To address such concerns, we present our ongoing work for mediating the way MAR Content, e.g., digital objects rendered on top of a video stream, is generated, distributed, and consumed by applications. We introduce a theoretical model, a supporting framework, as well as SpaceMediator, a proof-of-concept application implementing our approach. Luis Claramunt, Larissa Pokam Epse, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 3 |
| 2021 | Poster: DyPolDroid: User-Centered Counter-Policies Against Android Permission-Abuse AttacksabstractAndroid applications are extremely popular, as they are used for banking, social media, e-commerce, etc. However, several malicious applications have recently carried out data leaks and spurious credit card charges by abusing the Android Permissions granted initially to them by unaware users in good faith. To alleviate this pressing concern, we present DyPolDroid, a dynamic, semi-automated security framework that builds upon Android Enterprise, a device-management framework for organizations, allowing for users to design and enforce custom Counter-Policies, effectively protecting against such malicious applications without requiring advanced security and/or technical expertise. Matthew Hill, Carlos E. Rubio-Medrano, Luis Claramunt, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 2 |
| 2021 | Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service
Adam Oest, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang 0001, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
USENIX Security Symposium | 4 |
| 2020 | HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsabstractIndustrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis. Efrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001, Tiffany Bao, Gail-Joon Ahn |
CCS | 2 |
| 2020 | Proactive Risk Assessment for Preventing Attribute-Forgery Attacks to ABAC PoliciesabstractRecently, the use of well-defined, security-relevant pieces of runtime information, a.k.a., attributes, has emerged as a convenient paradigm for writing, enforcing, and maintaining authorization policies, allowing for extended flexibility and convenience. However, attackers may try to bypass such policies, along with their enforcement mechanisms, by maliciously forging the attributes listed on them, e.g., by compromising the attribute sources : operative systems, software modules, remote services, etc., thus gaining unintended access to protected resources as a result. In such a context, performing a proper risk assessment of authorization policies, taking into account their inner structure: rules, attributes, combining algorithms, etc., along with their corresponding sources, becomes highly convenient to overcome \emphzero-day vulnerabilities, before they can be later exploited by attackers. With this in mind, we introduce \toolname, an automated risk assessment framework for authorization policies, which, besides being inspired by well-established techniques for vulnerability analysis such as symbolic execution, also introduces the very first approach for proactively assessing risks in the context of a series of attacks based on unintended attribute manipulation via forgery. We validate our approach by resorting to a set of case studies we performed on both real-life policies originally written in the English language, as well as a set of policies obtained from the literature, which show not only the convenience of our approach for risk assessment, but also reveal that some of those policies are vulnerable to attribute-forgery attacks by just compromising one or two of their attributes. Carlos E. Rubio-Medrano, Luis Claramunt, Shaishavkumar Jogani, Gail-Joon Ahn |
SACMAT | 1 |
| 2019 | Understanding and Predicting Private Interactions in Underground ForumsabstractThe studies on underground forums and marketplaces have significantly advanced our understandings of cybercrime workflows and underground economies. Researchers of underground economies have conducted comprehensive studies on public interactions. However, little research focuses on private interactions. The lack of the investigation on private interactions may cause misunderstandings on underground economies, as users in underground forums and marketplaces tend to share the minimal amount of information in public interactions and resort to private messages for follow-up conversations. In this paper, we propose methods to investigate the underground private interactions and we analyze a recently leaked dataset from Nulled.io. We present analyses on the contents and purposes of private messages. In addition, we design machine learning-based models that only use the publicly available information to detect if two underground users privately communicate with each other. Finally, we perform adversarial analysis to evaluate the robustness of the detector to different types of attacks. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Tiffany Bao, Adam Doupé, Gail-Joon Ahn |
CODASPY | 2 |
| 2019 | Towards Effective Verification of Multi-Model Access Control PropertiesabstractMany existing software systems like logistics systems or enterprise applications employ data security in a more or less ad hoc fashion. Our approach focuses on access control such as permission-based discretionary access control (DAC), variants of role-based access control (RBAC) with delegation, and attribute-based access control (ABAC). Typically, software systems implement hybrid access control making an effective security analysis and assessment rather difficult. Bernhard J. Berger, Christian Maeder, Rodrigue Wete Nguempnang, Karsten Sohr, Carlos E. Rubio-Medrano |
SACMAT | 5 |
| 2019 | Effectively Enforcing Authorization Constraints for Emerging Space-Sensitive TechnologiesabstractRecently, applications that deliver customized content to end-users, e.g., digital objects on top of a video stream, depending on information such as their current physical location, usage patterns, personal data, etc., have become extremely popular. Despite their promising future, some concerns still exist with respect to the proper use of such space-sensitive applications (S-Apps) inside independently-run physical spaces, e.g., schools, museums, hospitals, memorials, etc. Based on the idea that innovative technologies should be paired with novel (and effective) security measures, this paper proposes space-sensitive access control (SSAC), an approach for restricting space-sensitive functionality in such independently-run physical spaces, allowing for the specification, evaluation and enforcement of rich and flexible authorization policies, which, besides meeting the specific needs for S-Apps, are also intended to avoid the need for interruptions in their normal use as well as repetitive policy updates, thus providing a convenient solution for both policy makers and end-users. We present a theoretical model, a proof-of-concept S-App, and a supporting API framework, which facilitate the policy crafting, storage, retrieval and evaluation processes, as well as the enforcement of authorization decisions. In addition, we present a performance case study depicting our proof-of-concept S-App in a set of realistic scenarios, as well as a user study which resulted in 90% of participants being able to understand and write authorization policies using our approach, and 93% of them also recognizing the need for restricting functionality in the context of emerging space-sensitive technologies, thus providing evidence that encourages the adoption of SSAC in practice. Carlos E. Rubio-Medrano, Shaishavkumar Jogani, Maria Leitner, Ziming Zhao 0001, Gail-Joon Ahn |
SACMAT | 1 |
| 2015 | Federated Access Management for Collaborative Network Environments: Framework and Case StudyabstractWith the advent of various collaborative sharing mechanisms such as Grids, P2P and Clouds, organizations including private and public sectors have recognized the benefits of being involved in inter-organizational, multi-disciplinary, and collaborative projects that may require diverse resources to be shared among participants. In particular, an environment that often makes use of a group of high-performance network facilities would involve large-scale collaborative projects and tremendously seek a robust and flexible access control for allowing collaborators to leverage and consume resources, e.g., computing power and bandwidth. In this paper, we propose a federated access management scheme that leverages the notion of attributes. Our approach allows resource-sharing organizations to provide distributed provisioning (publication, location, communication, and evaluation) of both attributes and policies for federated access management purposes. Also, we provide a proof-of-concept implementation that leverages distributed hash tables (DHT) to traverse chains of attributes and effectively handle the federated access management requirements devised for inter-organizational resource sharing and collaborations. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
SACMAT | 1 |
| 2014 | Achieving security assurance with assertion-based application constructionabstractModern software applications are commonly builtby leveraging pre-fabricated modules, e.g. application programming interfaces (APIs), which are essential to implement the desired functionalities of software applications, helping reduce the overall development costs and time. When APIs deal with sec Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
CollaborateCom | 1 |
| 2013 | Supporting secure collaborations with attribute-based access controlabstractAttribute-based access control (ABAC) has been regarded in recent years as an effective way for providing security guarantees in collaboration environments, due to its alleged flexibility and efficiency for meeting the access control requirements of heterogeneous organizations. Despite the growing Carlos E. Rubio-Medrano, Clinton D'Souza, Gail-Joon Ahn |
CollaborateCom | 1 |
| 2013 | Verifying Access Control Properties with Design by Contract: Framework and Lessons LearnedabstractEnsuring the correctness of high-level security properties including access control policies in mission-critical applications is indispensable. Recent literature has shown how immaturity of such properties has caused serious security vulnerabilities, which are likely to be exploited by malicious parties for compromising a given application. This situation gets aggravated by the fact that modern applications are mostly built on previously developed reusable software modules and any failures in security properties in these reusable modules may lead to vulnerabilities across associated applications. In this paper, we propose a framework to address this issue by adopting Design by Contract (DBC) features. Our framework accommodates security properties in each application focusing on access control requirements. We demonstrate how access control requirements based on ANSI RBAC standard model can be specified and verified at the source code level. Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
COMPSAC | 1 |