Eduardo Viegas 0001

dblp:120/2495-1 · also Eduardo K. Viegas, Eduardo Kugler Viegas · DBLP profile ↗
← Back
57ranked-venue papers
10as first author
39since 2021 · last 2026
0000-0002-5050-6363ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 5 first-author · 12 since 2021Systems, architecture and hardware · 10 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Large Language Model Framework for Predicting Judicial Outcomes in Civil Law Systems
Alan Alves Araújo, Altair Olivo Santin, Eduardo Viegas 0001
ICPR (1)3
2026 Sparse Mixture of Experts for Image-Based Multi-View Android Malware Detection
Jhonatan Geremias, Alceu S. Britto Jr., Altair Olivo Santin, Eduardo Viegas 0001
IWCMC4
2026 A Feature Selection Model for Lightweight Network Intrusion Detection on Resource-constrained Devices
Wadson S. Pereira, Eliane Maria T. Barbosa, Altair Olivo Santin, Eduardo Viegas 0001
IWCMC4
2026 Diversity as a Security Primitive for ML-Based Network Intrusion Detection
Allan Espindola, Altair Olivo Santin, Eduardo Viegas 0001, Pedro M. Ferreira 0001, António Casimiro
NetSoft3
2026 Toward an Intrusion Detection System for a Virtualization Framework in Edge Computing
abstract
Edge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks.
Everton de Matos, Hazaa Alameri, Willian Tessaro Lunardi, Martin Andreoni, Eduardo Viegas 0001
WCNC5
2026 Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems
abstract
Traditional Intrusion Detection Systems (IDSs) struggle with unseen attacks, a critical gap in industrial settings, while single-view approaches lack cross-context detection for attacks that manifest across host and network layers. We propose DIversity-driven Multi-view Ensemble IDS (DIME-IDS), a diversity-driven multi-view ensemble for Supervisory Control and Data Acquistion (SCADA) systems, which manage critical industrial infrastructures. Our work introduces: (i) A public hybrid SCADA dataset with 16 attack behaviors synchronized across four Linux/Windows views (network, host, user-activity, system-activity); (ii) A novel Nondominated Sorting Genetic Algorithm II (NSGA-II) optimization constructing ensembles that maximize both accuracy and inter-view diversity; (iii) Dynamic classifier selection at inference using Pareto-optimal operation points. Evaluated against strong baselines (XGB/RF/MLP), DIME-IDS achieves 0.86 accuracy, 0.95 AUC, and 6.51% False Negative (FN) rate, outperforming single-view (10.03%) and concatenated (14.38%) approaches, with lowest FN rates in 3 of 4 unseen attacks. These results demonstrate that explicit multi-view diversity and dynamic selection significantly enhance generalization against novel threats in industrial environments.
Allan Espindola, António Casimiro, Altair Olivo Santin, Pedro M. Ferreira 0001, Eduardo Viegas 0001
Future Gener. Comput. Syst.5
2025 On the Challenges of Implementing MLOps for Stream Learning Algorithms
Miguel G. Rodrigues, Eduardo Viegas 0001, Fabrício Enembreck, Altair Olivo Santin, Juliano S. Langaro, Adilson G. Filho
AINA (3)2
2025 Evaluating Parental Readiness to Manage Children's Privacy Across Social Media Platforms
abstract
Children’s widespread use of digital platforms has intensified concerns about the adequacy of privacy protections. Current legislation places the responsibility for managing children’s privacy on parents and guardians, assuming they possess the necessary knowledge to make informed decisions. In light of this, this work assesses parental maturity in managing children’s privacy on social platforms. First, we identify the main privacy attributes relevant to children’s online data protection by analyzing existing laws and regulations, including the GDPR, COPPA, and LGPD. This phase establishes a regulatory baseline for evaluating parental responsibilities and expectations. In the second phase, we surveyed 77 parents and guardians to assess their level of maturity in managing privacy-related measures and to evaluate how effectively they can protect their children’s data in digital environments. Our results reveal a significant discrepancy between perceived and actual knowledge, suggesting that many parents may not be adequately prepared to fulfill the role expected by current regulations. These findings support the need for clearer policies and a shared responsibility model between platforms and guardians to ensure child privacy.
Mykaele F. Abreu, Eduardo Viegas 0001, Altair Olivo Santin, Jhonatan Geremias
SMC2
2025 A Federated Learning Model for Privacy-Preserving and Cross-Domain Kidney Stone Detection in Medical Imaging
abstract
Kidney stones significantly impact healthcare systems, with diagnosis typically requiring time-consuming Computed Tomography (CT) scan consultations between physicians and radiologists, often delaying patient care. Achieving a quick and accurate diagnosis is essential to ensure timely and effective treatment, which has motivated the development of Deep Neural Network (DNN)-based approaches for automated kidney stone detection. However, building effective models remains challenging, as it often requires access to large and diverse datasets that are siloed across institutions, and sharing such medical data is rarely feasible due to strict privacy regulations and patient confidentiality concerns. This paper proposes a privacy-preserving Federated Learning (FL) framework that enables multiple medical institutions to collaboratively train a DNN model without sharing sensitive patient data. Each institution trains a local model on its private dataset, and a centralized trusted server securely aggregates model parameters. We evaluate our approach using abdominal CT scan image datasets from two distinct institutions. Experimental results demonstrate that our proposed model achieves high classification accuracy within the same training environment, with an F1-score of up to 0.94. In addition, in cross-dataset evaluations, our approach outperforms traditional centralized baselines, showing significantly lower performance degradation while preserving patient privacy.
Lucas Sotomaior, Luiz F. B. Fonseca, Matheus A. C. Zangari, Rodrigo K. Krebs, Alceu S. Britto Jr., Eduardo Viegas 0001
SMC6
2025 An Energy-Efficient Intrusion Detection Offloading Based on DNN for Edge Computing
abstract
To address the computational limitations associated with implementing Deep Neural Network (DNN)–based intrusion detection on resource-constrained devices, this work proposes an energy-efficient edge architecture that integrates distributed early-exit DNN models to minimize processing overhead while preserving detection performance. Our approach employs multi-objective optimization to dynamically offload complex tasks to the cloud, thereby balancing the trade-off between accuracy and energy consumption under operator constraints. Furthermore, it incorporates a rejection mechanism and confidence calibration via temperature scaling to ensure reliability as network traffic evolves. Experiments on a 7TB year-long dataset demonstrate that the system reduces edge energy consumption to only 1% while offloading only 10% of events, all without compromising detection accuracy and even improving the F1-Score by 0.02 compared to traditional approaches.
João A. Simioni, Eduardo Viegas 0001, Altair Olivo Santin, Everton de Matos
IEEE Internet Things J.2
2025 A MLOps architecture for near real-time distributed Stream Learning operation deployment
Miguel G. Rodrigues, Eduardo Viegas 0001, Altair Olivo Santin, Fabrício Enembreck
J. Netw. Comput. Appl.2
2024 A Review of Social Network Regulations and Mechanisms for Safeguarding Children's Privacy
Mykaele F. Abreu, Eduardo Viegas 0001, Altair Olivo Santin
AINA (5)2
2024 A Non-interactive One-Time Password-Based Method to Enhance the Vault Security
Juarez Oliveira, Altair Olivo Santin, Eduardo Viegas 0001, Pedro Horchulhack
AINA (4)3
2024 A Multi-View Android Malware Detection Model Through Multi-Objective Optimization
abstract
Over the past few years, several highly accurate Machine Learning (ML) techniques have been proposed for Android malware detection. Unfortunately, proposed schemes are rarely used in production, a situation usually caused by their limited generalization capabilities, leading to low accuracies when deployed. This paper proposes a new multi-view Android malware detection model, implemented in two stages. First, we extract multiple feature sets from an analyzed Android application package. The feature sets provide a complementary Android app behavioral vector for the classification task, enhancing the system's generalization. Secondly, we conduct a multi-objective optimization to select the optimal feature subset from each view for subsequent ensemble-based classification. Our proposal's insight is to proactively select each feature subset that simultaneously improves accuracy and reduces processing requirements in a multi-view setting. Experiments on our new dataset, comprising over 40 thousand Android app samples, demonstrated the feasibility of our proposal. Our scheme can improve true-positive rates by an average of 4.4 while demanding only up to 65% of inference processing costs.
Philipe Fransozi, Jhonatan Geremias, Eduardo Viegas 0001
ICMLA3
2024 Towards a Feasible Palm Vein Verification Scheme Using Deep Autoencoder and Siamese Networks
abstract
Palm vein pattern recognition offers a unique personal identification feature. Unfortunately, these techniques typically require a Near Infrared (NIR) camera sensor to extract the individual's venous pattern, challenging their wide deployment. This paper proposes a new feasible palm vein verification scheme using a Deep Autoencoder and a Siamese Network, implemented threefold. First, we capture the individual's palm using a traditional visible spectrum camera sensor and perform preprocessing tasks to correct imprecise positioning, easing palm support accessories requirements. Second, we eliminate NIR sensor requirement by fine-tuning a Deep Autoencoder model to convert images from the visible spectrum to their infrared counterparts. Third, generated images are processed by a lightweight Siamese network using a contrastive loss function for individual verification. Experiments conducted on a publicly available dataset with over a hundred individuals confirmed the feasibility of our proposal. Our scheme reaches up to 0.97 of true-negative rate, with only 0.01 decrease compared to traditional NIR-based approaches. In addition, individual identification can be conducted in less than 6 seconds in a resource-constrained environment thanks to our lightweight model's implementation.
Mateus Nunes, Eduardo Viegas 0001, Altair Olivo Santin
ICMLA2
2024 Passive Identification of Rogue Industrial Access Points Using a One-Class Machine Learning Model
abstract
Access point (AP) security has become increasingly important as wireless local area networks (WLANs) proliferate in industrial environments. Rogue APs are often used by attackers to conduct man-in-the-middle (MiTM) attacks. They can redirect users to malicious servers or do eavesdropping and manipulation of their communications.In this paper, we propose a novel one-class machine learning model to passively identify rogue APs in industrial environments. The implementation of the model is twofold. First, we passively extract the hardware and software characteristics of the evaluated AP according to its generated messages. This results in a comprehensive feature set that captures both low-level and high-level behaviors of the evaluated AP.Second, we apply a one-class machine learning model to identify APs that significantly deviate from the previously known profile of legitimate APs. The combined evaluation of hardware and software behaviors integrated with an outlier detection scheme to effectively identify rogue APs is the insight of our proposal. We demonstrate the feasibility of our model, achieving an F1 score of 0.89 and a true positive rate of 0.9 in experiments conducted on our new publicly available dataset of 357 unique AP behaviors.
André L. de S. Paula, Eduardo Viegas 0001, Altair Olivo Santin
IECON2
2024 Toward a Reliable Network-Based Intrusion Detection Model for SCADA: A Classification with Reject Option Approach
abstract
Industrial control systems (ICS) are often targeted by highly motivated attackers seeking to disrupt their services due to its critical nature. Traditional cybersecurity does not provide the necessary reliability for ICS systems. Even when implemented with many layers of defense, including network intrusion detection systems (NIDS). This paper proposes a dynamic and reliable intrusion detection model that is implemented in two steps. First, it proactively classifies each type of possible network attack on the basis of the current network traffic behavior. Second, it evaluates the classification quality through rejection option, which is an indication of its reliability. By adapting to the evolving network traffic, our proposal increases the system robustness against motivated attackers. The proposed model effectiveness has been demonstrated by experimenting in a controlled testbed with more than 14 attack categories. The dynamic selection of security mechanisms allowed us to increase the detection accuracy by up to 26%. Moreover, the classification evaluation in the proposed model achieves up to 99% detection accuracy with only 1% rejection.
Paulo Roberto de Oliveira, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Everton de Matos
IJCNN2
2024 Network-based Intrusion Detection Through Image-based CNN and Transfer Learning
abstract
Machine learning (ML) techniques for network intrusion detection is still limited in production environments despite promising results reported in the literature. Network traffic behavior exhibits considerable variability and evolves over time, requiring periodic model updates. This paper proposes a new approach to intrusion detection modeling based on CNN and transfer learning to reduce updating overhead. Its implementation is twofold. First, CNN is implemented using flow-based feature expansion derived from neural flattened hyperdimensional space. This expanded space representation contributes to a longer model lifetime and maintains system accuracy over time. Second, the required training data and computational cost are significantly reduced by performing periodic model updates based on a transfer learning approach. Experiments on a novel dataset with over 2.6 TB of data and one year of real-world network traffic demonstrate the feasibility of the proposal. Our proposal improves the average F1 score by up to 0.19 when no model updates are performed. While improving the system’s accuracy, model updates impose only 42.8% of the computational cost.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, João A. Simioni
IWCMC2
2024 Detection of quality of service degradation on multi-tenant containerized services
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Felipe Ramos, Pietro Tedeschi
J. Netw. Comput. Appl.2
2023 Context-Aware Security in the Internet of Things: A Review
Everton de Matos, Eduardo Viegas 0001, Ramão Tiago Tiburski, Fabiano Hessel
AINA (3)2
2023 A Dynamic Machine Learning Scheme for Reliable Network-Based Intrusion Detection
Eduardo Viegas 0001, Everton de Matos, Paulo Roberto de Oliveira, Altair Olivo Santin
AINA (2)1
2023 Towards a Reliable Hierarchical Android Malware Detection Through Image-based CNN
abstract
The number of Android malicious applications keeps growing as time passes, even paving their way to official app markets. In recent years, a promising malware detection approach makes use of the compiled app source codes (dex), through convolutional neural networks (CNN) as an image classification task. Unfortunately, current proposals often rely on unrealistic datasets, focusing their detection on the mal-ware families, while neglecting the detection of malware apps in the first place. In this paper, we propose a reliable and hierarchical Android malware detection through an image-based CNN scheme, implemented twofold. First, Android malware classification is performed in a hierarchically-structured local manner, initially identifying malware apps, then, their related family. Second, to ensure reliability and improve classification accuracy, only highly confident classified apps are reported, in a classification with reject option rationale. Experiments performed in a new dataset with over 26 thousand Android apps, divided into 29 malware families, compounding over 13 GB of app dex images, have shown that current image-based CNN for malware detection is unable to provide high detection accuracies. In contrast, our proposed model is able to reliably detect malware apps, improving the true-negative rates by up to 5.5%, and the average true-positive rate of the malware families of accepted apps by up to 12.7%, while rejecting only 10% of Android apps.
Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack
CCNC2
2023 A Generative Adversarial Network-based Attack for Audio-based Condition Monitoring Systems
abstract
Over the last years, several machine learning techniques have been proposed for the condition monitoring of physical assets based on audio. As a result, adversaries have been trying to circumvent the reliability of deployed systems, typically through the generation of maliciously altered audio samples that are subsequently introduced as input by the model. However, altering the input in production settings is not always feasible, on the contrary, samples are often collected through a microphone, significantly increasing the attack execution effort. In this paper, we propose a realistic generative adversarial network attack for an audio-based condition monitoring system. We first train a generator and a discriminator with a joint objective of generating audio samples corresponding to the difference between the two classes, e.g., normal and faulty. Additionally, we test our approach by overlapping our generated audio on the samples collected by the microphone. Our main goal is the proposal of a GAN-based attack capable of generating audio samples that when overlaid with the original microphone-captured audio may induce misclassification given a target class. Experiments performed through our captured audio dataset from normal and broken unmanned aerial vehicle propellers show that the proposed attack achieved a mean success rate of 40%, decreasing the F-measure concerning random noise by 13.3%, 20%, and 37.8% for ResNet-18, AlexNet, and DenseNet-169 models, respectively.
Abdul Rahman Ba Nabila, Eduardo Viegas 0001, Abdelrahman AlMahmoud, Willian Tessaro Lunardi
CCNC2
2023 Towards a Reliable and Lightweight Onboard Fault Detection in Autonomous Unmanned Aerial Vehicles
abstract
This paper proposes a new model for onboard physical fault detection on autonomous unmanned aerial vehicles (UAV) through machine learning (ML) techniques. The proposal performs the detection task with high accuracies and minimal processing requirements while signaling an unreliable ML model to the operator, implemented in two main phases. First, a wrapper-based feature selection is performed to de-crease the feature extraction computational costs, coped with a classification assessment technique to identify ML model unreliability. Second, physical UAV faults are signaled through a multi-view rationale that evaluates a variety of UAV sensors while triggering alerts based on a sliding window scheme. Experiments performed on a real quadcopter UAV with a broken propeller use case shows the proposal's feasibility. Our model can decrease the false-positive rates up to only 0.4%, while also decreasing the computational costs by at least 43 % when compared to traditional techniques. Notwithstanding, it can identify ML model unreliability, signaling the UAV operator when model fine-tuning is needed.
Sai Srinadhu Katta, Eduardo Viegas 0001
ICRA2
2023 Towards a Robust Adversarial Patch Attack Against Unmanned Aerial Vehicles Object Detection
abstract
Object detection techniques for autonomous Un-manned Aerial Vehicles (UAV) are built upon Deep Neural Networks (DNN), which are known to be vulnerable to adversarial patch perturbation attacks that lead to object detection evasion. Yet, current adversarial patch generation schemes are not designed for UAV imagery settings. This paper proposes a new robust adversarial patch generation attack against object detection with UAVs. We build adversarial patches considering UAV-specific settings such as the UAV camera perspective, viewing angle, distance, and brightness changes. As a result, built patches can also degrade the accuracy of object detector models implemented with different initializations and architectures. Experiments conducted on the VisDrone dataset have shown the proposal's feasibility, achieving an attack success rate of up to 80% in a white-box setting. In addition, we also transfer the patch against DNN models with different initializations and different architectures, reaching attack success rates of up to 75% and 78%, respectively, in a gray-box setting. GitHub: https://github.com/SamSamhuns/yolov5_adversarial
Samridha Shrestha, Saurabh Pathak, Eduardo Viegas 0001
IROS3
2023 Integrating VirtIO and QEMU on seL4 for Enhanced Devices Virtualization Support
abstract
Virtualization is a crucial technology for consolidating workloads and improving resource utilization in modern computing systems. seL4 is a small TCB (Trusted Computing Base) microkernel that can be used as a hypervisor to provide virtualization features. However, providing standard device interfaces to it remains a significant challenge in achieving secure and high-performance virtualization solutions for critical systems. To address this challenge, this paper proposes an approach that leverages the VirtIO standard through QEMU to provide a secure and efficient device virtualization solution for seL4. The feature takes advantage of seL4’s isolation guarantees and enables sharing of complex devices for multiple virtual machines, combined with the efficient communication interface provided by the VirtIO standard. We implemented and evaluated the approach using a set of benchmarks. The proposed approach leverages the VirtIO standard through QEMU on top of the seL4, aiming to offer a virtualization solution that accelerates development speed and enhances architectural flexibility by eliminating the need for native drivers.
Everton de Matos, Conor Lennon, Eduardo Viegas 0001, Markku Ahvenjärvi, Hannu Lyytinen, Joonas Onatsu, Anh Huy Bui
TrustCom3
2023 A Dynamic Network-based Intrusion Detection Model for Industrial Control Systems
abstract
Industrial Control Systems (ICS) play a crucial role in managing and controlling industrial assets. Due to their critical importance, adversaries are often highly motivated to target these systems, as a successful attack can disrupt the entire industry’s operations. In general, to improve the system’s security, proposed intrusion detection schemes often resort to traditional security mechanisms. As a consequence, due to their static nature, attackers can easily evade designed detection approaches. In light of this, this paper proposes a new dynamic network-based intrusion detection model for ICS, implemented in two phases. First, our scheme extracts network-related features to describe the current ICS environment behavior. Second, the security mechanisms are proactively selected based on the extracted network traffic behavior. As a result, our scheme can adjust the system’s configuration based on the current assessed event. Experiments on a new dataset, featuring over 14 attack categories targeting a SCADA system revealed that traditional detection methods face challenges in handling diverse attack categories. Conversely, our proposed model improved the average true-positive rates by up to 20% while also improving the range of detected attacks.
Paulo Roberto de Oliveira, Altair Olivo Santin, Pedro Horchulhack, Eduardo Viegas 0001, Everton de Matos
TrustCom4
2023 Federated learning for reliable model updates in network-based intrusion detection
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Pietro Tedeschi
Comput. Secur.2
2023 Reinforcement Learning for Intrusion Detection: More Model Longness and Fewer Updates
abstract
Several works have used machine learning techniques for network-based intrusion detection over the past few years. While proposed schemes have been able to provide high detection accuracies, they do not adequately handle the changes in network traffic behavior as time passes. Researchers often assume that model updates can be performed periodically as needed, although this is not easily feasible in real-world scenarios. This paper proposes a new intrusion detection model based on a reinforcement learning approach that aims to support extended periods without model updates. The proposal is divided into two strategies. First, it applies machine learning scheme as a reinforcement learning task to long-term learning -maintaining high reliability and high classification accuracies over time. Second, model updates are performed using a transfer learning technique coped with a sliding window mechanism that significantly decreases the need for computational resources and human intervention. Experiments performed using a new dataset spanning 8TB of data and four years of real network traffic indicate that current approaches in the literature cannot handle the evolving behavior of network traffic. Nevertheless, the proposed technique without periodic model updates achieves similar accuracy rates to traditional detection schemes implemented with semestral updates. In the case of performing periodic updates on our proposed model, it decreases the false positives up to 8%, false negatives up to 34%, with an accuracy variation up to only 6%, while demanding only seven days of training data and almost five times fewer computational resources when compared to traditional approaches.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
IEEE Trans. Netw. Serv. Manag.2
2022 Detection of Service Provider Hardware Over-commitment in Container Orchestration Environments
abstract
The deployment of container-based services continues to increase as time passes, mainly due to its fast provision time and lower allocation overheads. Yet, the literature still neglects the performance degradation in containers due to multi-tenancy and service provider hardware over-commitment. This paper proposes a new hardware over-commitment detection for container orchestration environments, implemented twofold. First, the containerized hardware usage of deployed containers is continuously monitored in a non-intrusive manner, leveraging the container engine resource management interface. Second, collected features are used by a recurrent neural network model for detecting both container and service level hardware over-commitment, following a time-series rationale. Experiments run on a containerized Apache Spark distribution have shown that multi-tenancy and hardware over-commitment significantly affect its performance. In addition, our proposed model is able to detect hardware over-commitment with up to 91% of true-positive at the container level, and up to 93% true-positive at the service level.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM2
2022 Intrusion Detection Model Updates Through GAN Data Augmentation and Transfer Learning
abstract
Current machine learning techniques for network-based intrusion detection cannot handle the evolving behavior of network traffic, requiring periodic model updates to be conducted. Besides requiring huge amounts of labeled network traffic to be provided, traditional model updates demand expressive computational costs. This paper proposes a new feasible model update procedure implemented in two steps. First, we use a Generative Adversarial Network (GAN) to augment the sampled network traffic. Next, we use the augmented dataset to perform model updates through a transfer learning-based approach. Thus, our model can decrease both the number of instances that must be labeled and the computational costs during model updates. Our experiments on a one-year dataset with over 8 TB of data show that literature techniques cannot handle changes in network traffic behavior. In contrast, the proposed model without updates improved true-positive rates by up to 25.6%. With monthly model updates, it requires only 14% of computational costs and 2.3% of instances to be provided.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Jhonatan Geremias
GLOBECOM2
2022 A Machine Learning-Based Digital Twin Model for Pressure Prediction in the Fuel Injection System
abstract
Over the last years, the engine calibration task has mostly been conducted based on the engineers’ knowledge. As a result, considering the complexity of modern engines, finding the most suitable configuration for each situation has become an impractical and expensive task. Apart from causing engines to be produced with inadequate calibration configuration, it can also decrease the lifespan of their components, degrading their efficiency. This paper proposes a machine learning-based digital twin model for pressure prediction in a fuel injection system, split into two steps. First, we extract statistical engine features based on a predefined time window to represent the engine behavior over time. Second, a digital twin implemented through a machine learning model is used to predict pressure levels in the fuel injection system. As a result, the predicted values can be used to assist the engine common rail system module in avoiding undesired engine states. Experiments performed on a new dataset, built over a real diesel-based engine, consisting of 208 features and over 1.3 million instances, have shown the feasibility of our proposal. The proposed scheme can predict in an advance time of 0.1 seconds the pressure levels for a fuel injection system with only 0.057 RMSE. Moreover, it increases its error rate by only 10.6% if a 0.5-second time advance is required.
Edwin P. Duarte, Eduardo Viegas 0001, Altair Olivo Santin
IECON2
2022 Towards Multi-view Android Malware Detection Through Image-based Deep Learning
abstract
Over the last years, several works have proposed highly accurate Android malware detection techniques. Surprisingly, modern malware apps can still pave their way to official markets, thus, demanding the provision of more robust and accurate detection approaches. This paper proposes a new multi-view Android malware detection through image-based deep learning, implemented threefold. First, apps are evaluated according to several feature sets in a multi-view setting, thus, increasing the information provided for the classification task. Second, extracted feature sets are converted to an image format while maintaining the principal components of the data distribution, keeping the information for the classification task. Third, built images are jointly represented in a single shot, each in a predefined image channel, enabling the application of deep learning architectures. Experiments on a new version of a publicly available Android malware dataset composed of over 11 thousand Android apps have shown our proposal's feasibility. It reaches true-negative rates of up to 99.5% when implemented with a single-view approach with our new image-building technique. In addition, if our proposed multi-view scheme is used, the classification accuracies of malware families become more stable, reaching a true-positive rate of up to 98.7%.
Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack
IWCMC2
2022 Toward feasible machine learning model updates in network-based intrusion detection
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin
Comput. Networks2
2021 Improving Intrusion Detection Confidence Through a Moving Target Defense Strategy
abstract
Despite the promising results reported in the literature, the intrusion detection schemes cannot deal with new network traffic behaviors making such proposals unfeasible to be deployed in production environments. This paper presents an intrusion detection model that relies on a moving target defense strategy to face new network traffic behavior in a two stage process. First, the system select the most suitable classifiers set to assign a class (normal or attack) according to the current event behavior. Second, we evaluate if the performed classification is reliable by validating its confidence values. The goal is to ensure that only the higher confident classifications from the most suitable classifiers are used to trigger intrusion detection alerts, keeping the system reliable over time. Experiments performed on a dataset that spans over 97GB of data with seven categories of network traffic shows that current machine learning techniques cannot cope with novel traffic behavior, failing to detect up to four new traffic categories. In contrast, the proposed model can select the most confident classifiers, reducing the average false-negative rates by up to 39%, regardless of the current network traffic category.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM2
2021 A Reminiscent Intrusion Detection Model Based on Deep Autoencoders and Transfer Learning
abstract
Machine learning techniques for network-based intrusion detection often assume that network traffic does not change over time or that model updates can be easily performed. This paper proposes a novel, reminiscent intrusion detection model based on deep autoencoders and transfer learning to ease the model update burden in a twofold implementation. First, a deep autoencoder is used as an additional feature extraction stage to obtain a historical feature representation of network traffic. Second, at model updates, the deep autoencoder parameters are updated through a transfer learning procedure, thus, significantly decreasing the amount of needed labeled training data and the computational costs. Experiments performed on a 8TB dataset containing real and valid network traffic ranging for one year have shown that approaches in the literature cannot handle with the network traffic behavior changes over time, requiring impractical amounts of labeled data to be provided during model training tasks. In addition, if no model updates are performed, the proposed scheme can improve the true-negative rate by up to 23.9%. If done so, it can provide similar accuracy rates of traditional techniques while demanding only 22% of labeled training data and 28% of computational costs.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM2
2021 A Machine Learning Model for Detection of Docker-based APP Overbooking on Kubernetes
abstract
Resource allocation overbooking is an approach used by cloud providers that allocates more virtual resources than available on physical hardware, which may imply service quality degradation. Docker in cloud computing environments is being increasingly used due to their fast provisioning and deployment, while the impact of overbooking of resources allocation due to multi-tenancy remains overlooked. This paper proposes a machine learning model to detect overbooking in Kubernetes environments within the docker container. The proposed model continuously monitors distributed container OS usage and application performance metrics. The collected metrics are used as input to a machine learning model that identifies multi-tenancy interference incurring in application performance degradation. Experiments performed on a Kubernetes cluster with a Docker-based Big Data processing application showed that our proposed model could detect resource overbooking with up to 98% accuracy. This implies an overbooking on a resource of up to 1.2 in the client’s domain.
Felipe Ramos, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Roger Robson dos Santos, Allan Espindola
ICC2
2021 A Multi-View Intrusion Detection Model for Reliable and Autonomous Model Updates
abstract
Changes in network traffic behavior over time are neglected by authors who use machine learning techniques applied to intrusion detection. In general, it is assumed that periodic model updates are performed, regardless of the challenges related to such a task. This paper proposes a new multi-view intrusion detection model capable of reliably performing model updates without human assistance while also maintaining its accuracy over time. The proposal evaluates the classification’s confidence values in a multi-view configuration to maintain its reliability over time, even without model updates. Besides, it is able to perform model updates autonomously, according to the result of the multi-view classification. Our experiments, performed with 7TB of real network traffic over a 2-year interval, show that our proposed scheme can maintain its accuracy over time without model updates, rejecting only 14.2% of its classification. However, when autonomous model updates are performed, the rejection rate drops to just 8.8%, while also improving the model’s accuracy by 4.3%.
Rivaldo L. Tomio, Eduardo Viegas 0001, Altair Olivo Santin, Roger Robson dos Santos
ICC2
2021 A Deep Autoencoder and RNN Model for Indoor Localization with Variable Propagation Loss
abstract
Current machine learning techniques for indoor localization of wireless devices assume a single wireless propagation loss setting, making them unfeasible for reliable production deployment. This paper proposes a new indoor localization technique designed for variable propagation loss environments based on deep autoencoder and recurrent neural network (RNN), implemented threefold. This paper proposes a new indoor localization technique designed for variable loss propagation environments based on deep autoencoder and recurrent neural network (RNN), implemented in three stages. First, we extract statistical feature values from collected RSSI. Second, a deep autoencoder is used to remove wireless propagation noises introduced by variable fading settings. Third, an RNN performs the localization task taking into account previous sensor measurements. Experiments performed in 3 simulated testbeds with distinct propagation loss settings have shown that current approaches decrease localization accuracy by up to 30% when a different propagation loss is faced. In addition, our proposed model improved localization accuracy by up to 25.8% regardless of the current environment propagation loss.
Allan Espindola, Eduardo Viegas 0001, Andre Traleski, Marcelo Eduardo Pellenz, Altair Olivo Santin
WiMob2
2020 Identity and Access Management for IoT in Smart Grid
Vilmar Abreu, Altair Olivo Santin, Eduardo Viegas 0001, Vinicius Vielmo Cogo
AINA3
2020 A Long-Lasting Reinforcement Learning Intrusion Detection Model
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
AINA2
2020 Facing the Unknown: A Stream Learning Intrusion Detection System for Reliable Model Updates
Eduardo Viegas 0001, Altair Santin Santin, Vinicius Vielmo Cogo, Vilmar Abreu
AINA1
2020 A Reliable Semi-Supervised Intrusion Detection Model: One Year of Network Traffic Anomalies
abstract
Despite the promising results of machine learning for network-based intrusion detection, current techniques are not widely deployed in real-world environments. In general, proposed detection models quickly become obsolete, thus, generating unreliable classifications over time. In this paper, we propose a new reliable model for semi-supervised intrusion detection that uses a verification technique to provide reliable classifications over time, even in the absence of model updates. Additionally, we cope with this verification technique with semi-supervised learning to autonomously update the underlying machine learning models without human assistance. Our experiments consider a full year of real network traffic and demonstrate that our solution maintains the accuracy rate over time without model updates while rejecting only 10.6% of instances on average. Moreover, when autonomous (non-human-assisted) model updates are performed, the average rejection rate drops to just 3.2% without affecting the accuracy of our solution.
Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo, Vilmar Abreu
ICC1
2020 A Host-based Intrusion Detection Model Based on OS Diversity for SCADA
abstract
Supervisory Control and Data Acquisition (SCADA) systems have been a frequent target of cyberattacks in Industrial Control Systems (ICS). As such systems are a frequent target of highly motivated attackers, researchers often resort to intrusion detection through machine learning techniques to detect new kinds of threats. However, current research initiatives, in general, pursue higher detection accuracies, neglecting the detection of new kind of threats and their proposal detection scope. This paper proposes a novel, reliable host-based intrusion detection for SCADA systems through the Operating System (OS) diversity. Our proposal evaluates, at the OS level, the SCADA communication over time and, opportunistically, detects, and chooses the most appropriate OS to be used in intrusion detection for reliability purposes. Experiments, performed through a variety of SCADA OSs front-end, shows that OS diversity provides higher intrusion detection scope, improving detection accuracy by up to 8 new attack categories. Besides, our proposal can opportunistically detect the most reliable OS that should be used for the current environment behavior, improving by up to 8%, on average, the system accuracy when compared to a single OS approach, in the best case.
Bruno B. Bulle, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos
IECON3
2020 Towards Real-time Video Content Detection in Resource Constrained Devices
abstract
Convolutional neural networks have been successfully applied for video content detection in the last years. However, such cognitive models usually demand the availability of several gigabytes of memory and present a low detection throughput, as a result, they are not feasible for resource-constrained devices, especially for real-time applications like video streaming. In this paper, we address real-time video content detection in resource-constrained devices in a threefold manner. First, we improve detection throughput by means of a frame sampling technique. Then, we propose a new evaluation measure towards proper deployment of convolutional neural networks in resource-constrained devices. Finally, we address the accuracy degradation caused by the porting of the convolutional neural network, applying a lightweight classification verification technique. The evaluation results, through a real-time demanding application, show that the proposed approach can detect up to 301 frames/sec, demanding only 9 megabytes of memory while reaching up to 89.3% of accuracy. Besides, we can increase the detection throughput by up to 10 times, with no effects on accuracy, and further increase accuracy without effects on processing demands.
Jhonatan Geremias, Altair Olivo Santin, Eduardo Viegas 0001, Alceu S. Britto Jr.
IJCNN3
2020 A Lightweight Network-based Android Malware Detection System
Igor Jochem Sanz, Martin Andreoni, Eduardo Viegas 0001, Vinicius Rodrigues Sanches
Networking3
2020 PPCensor: Architecture for real-time pornography detection in video streaming
Jackson Mallmann, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos, Jhonatan Geremias
Future Gener. Comput. Syst.3
2019 BigFlow: Real-time and reliable anomaly-based intrusion detection for high-speed networks
Eduardo Viegas 0001, Altair Olivo Santin, Alysson Neves Bessani, Nuno Neves 0001
Future Gener. Comput. Syst.1
2019 SDN-based and multitenant-aware resource provisioning mechanism for cloud-based big data streaming
Cleverton Vicentini, Altair Olivo Santin, Eduardo Viegas 0001, Vilmar Abreu
J. Netw. Comput. Appl.3
2018 A Machine Learning Auditing Model for Detection of Multi-Tenancy Issues Within Tenant Domain
abstract
Cloud computing is intrinsically based on multi-tenancy, which enables a physical host to be shared amongst several tenants (customers). In this context, for several reasons, a cloud provider may overload the physical machine by hosting more tenants that it can adequately handle. In such a case, a tenant may experience application performance issues. However, the tenant is not able to identify the causes, since most cloud providers do not provide performance metrics for customer monitoring, or when they do, the metrics can be biased. This study proposes a two-tier auditing model for the identification of multi-tenancy issues within the tenant domain. Our proposal relies on machine learning techniques fed with application and virtual resource metrics, gathered within the tenant domain, for identifying overloading resources in a distributed application context. The evaluation using Apache Storm as a case study, has shown that our proposal is able to identify a node experiencing multi-tenancy interference of at least 6%, with less than 1% false-positive or false-negative rates, regardless of the affected resource. Nonetheless, our model was able to generalize the multi-tenancy interference behavior based on private cloud testbed monitoring, for different hardware configurations. Thus, a system administrator can monitor an application in a public cloud provider, without possessing any hardware-level performance metrics.
Cleverton Vicentini, Altair Olivo Santin, Eduardo Viegas 0001, Vilmar Abreu
CCGrid3
2018 Enabling Anomaly-based Intrusion Detection Through Model Generalization
abstract
Anomaly-based intrusion detection by the means of machine learning techniques is extensively studied in the literature mainly due to its promise to detect new attacks. However, despite the promising reported results, it is hardly deployed to real world environments. The main challenge in its adoption is the discrepancy between the accuracy rates obtained during the classifier development process and the rates obtained during its use in production environments. Such a discrepancy is mainly caused by non-representative training databases and nongeneralizable (scenario-specific) classifier's model. This paper presents a method to create intrusion databases, which aims at mimicking the production environments characteristics by using well-known tools. Moreover, we present and evaluate a new validation technique, which aims at ensuring the generalization capacity of the obtained models, reached using cross-validating with different intrusion databases. The evaluation tests showed the feasibility of the proposed method. The feature selection technique ensured the model generalization capacity, improving its accuracy rate by 13%, while testing in different intrusion databases. Finally, the proposed anomaly-based approach was compared with Snort, reaching an accuracy rate of 99% against 27% of Snort for detecting DoS attacks.
Eduardo Viegas 0001, Altair Olivo Santin, Vilmar Abreu, Luiz Eduardo Soares de Oliveira
ISCC1
2018 A reliable and energy-efficient classifier combination scheme for intrusion detection in embedded systems
Eduardo Viegas 0001, Altair Olivo Santin, Luiz Oliveira 0003, André França 0001, Ricardo P. Jasinski, Volnei A. Pedroni
Comput. Secur.1
2017 A Resilient Stream Learning Intrusion Detection Mechanism for Real-Time Analysis of Network Traffic
abstract
The number of novel attacks observed in networked systems increases every day. Due to the large amount of generated data over the network, its storage for further analysis may not be feasible. Moreover, current attacks are becoming more sophisticated, as the attackers are attempting to evade traditional intrusion detection mechanisms by perverting their properties. This paper presents a novel real-time (ongoing) network traffic measurement approach that supports resilient analysis for stream learning intrusion detection. The network data is grouped at runtime according to its characteristics, while each network traffic flow is discretized at regular time intervals. Each network flow is classified by a multi-view stream learning classifiers pool, defining the network flow class through a majority voting approach. The proposal is able to provide resiliency to the classifiers even for the detection of unknown attacks. The evaluation tests for the average operation point (25 views) provides an increase in the system resilience to adversarial attacks of 22 % when compared to traditional approaches. Moreover, in the scalability experiments with a 10-node (single core each) cluster testbed, the network flow measurement solution (1 view) reached 1.38 Gbps throughput, while the proposed resilient stream learning intrusion detection with 25 views reached a throughput of 1.19 Gbps.
Eduardo Viegas 0001, Altair Olivo Santin, Nuno Neves 0001, Alysson Neves Bessani, Vilmar Abreu
GLOBECOM1
2017 A multi-domain role activation model
abstract
Organizations establish partnerships in order to achieve a strategic goal. In many cases, resources in a given organization are accessed from external domains, characterizing multi-domain operations. This paper presents an approach to perform role activation in multi-domain environments. The active roles are imported in other domains from a user's home domain. Thus, a Single Role Activation (SRA) is performed, similarly to Single Sign-On (SSO) authentication. The administrative autonomy to define each role permission is kept within each local domain. We evaluated the proposal by implementing a prototype to provide support for SRA, based on RESTful web services and standardized specifications such as XACML and OpenID Connect. The prototype evaluation measured response time for simultaneous access requests, with SRA showing better results when compared to traditional role activation. Furthermore, from a security perspective, the proposal is about 15 times faster than traditional approaches.
Vilmar Abreu, Altair Olivo Santin, Eduardo Viegas 0001, Maicon Stihler
ICC3
2017 Stream learning and anomaly-based intrusion detection in the adversarial settings
abstract
Despite existing many anomaly-based intrusion detection studies in the literature, they are not frequently adopted by the industry in production environments (products). Such a usage gap occurs mainly due to the difficulty to maintain the detection rate in acceptable level, given the occurrence of false alarms. In general, the literature does not consider the adversarial settings, when an opponent attempt to evade the detection system, thus possibly rendering the system unreliable over time. In this paper, we propose and evaluate a new approach to reliably perform real time stream learning for anomaly-based intrusion detection. We employ a class-specific stream outlier detector to automatically update the intrusion detection engine over the time, and a rejection mechanism, which makes it possible to obtain indications that an evasion attempt might being happening. Furthermore, the proposal is resilient to causative attacks, providing a secure intrusion detection mechanism even when the attacker can inject misclassified instances in the training dataset. The evaluation tests show that the proposed approach is resilient to exploratory attacks, allowing the system administrator to know when an evasion attempt might be occurring.
Eduardo Viegas 0001, Altair Olivo Santin, Vilmar Abreu, Luiz Eduardo Soares de Oliveira
ISCC1
2017 Toward a reliable anomaly-based intrusion detection in real-world environments
Eduardo Viegas 0001, Altair Olivo Santin, Luiz Eduardo Soares de Oliveira
Comput. Networks1
2017 Towards an Energy-Efficient Anomaly-Based Intrusion Detection Engine for Embedded Systems
abstract
Nowadays, a significant part of all network accesses comes from embedded and battery-powered devices, which must be energy efficient. This paper demonstrates that a hardware (HW) implementation of network security algorithms can significantly reduce their energy consumption compared to an equivalent software (SW) version. The paper has four main contributions: (i) a new feature extraction algorithm, with low processing demands and suitable for hardware implementation; (ii) a feature selection method with two objectives - accuracy and energy consumption; (iii) detailed energy measurements of the feature extraction engine and three machine learning (ML) classifiers implemented in SW and HW-Decision Tree (DT), Naive-Bayes (NB), and k-Nearest Neighbors (kNN); and (iv) a detailed analysis of the tradeoffs in implementing the feature extractor and ML classifiers in SW and HW. The new feature extractor demands significantly less computational power, memory, and energy. Its SW implementation consumes only 22 percent of the energy used by a commercial product and its HW implementation only 12 percent. The dual-objective feature selection enabled an energy saving of up to 93 percent. Comparing the most energy-efficient SW implementation (new extractor and DT classifier) with an equivalent HW implementation, the HW version consumes only 5.7 percent of the energy used by the SW version.
Eduardo Viegas 0001, Altair Olivo Santin, André França 0001, Ricardo P. Jasinski, Volnei A. Pedroni, Luiz Eduardo Soares de Oliveira
IEEE Trans. Computers1