EDBT 2026 Demo / reviewers in the wild / expert
Alberto Blanco-Justicia
dblp:133/8414
· DBLP profile ↗
20ranked-venue papers
8as first author
9since 2021 · last 2024
0000-0002-1108-8082ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 3 first-author · 4 since 2021Security and privacy · 6 · 3 first-author · 2 since 2021Computer networks · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | An Examination of the Alleged Privacy Threats of Confidence-Ranked Reconstruction of Census Microdata
David Sánchez 0001, Najeeb Jebreel, Krishnamurty Muralidhar, Josep Domingo-Ferrer, Alberto Blanco-Justicia |
PSD | 5 |
| 2024 | LFighter: Defending against the label-flipping attack in federated learning
Najeeb Jebreel, Josep Domingo-Ferrer, David Sánchez 0001, Alberto Blanco-Justicia |
Neural Networks | 4 |
| 2024 | Enhanced Security and Privacy via Fragmented Federated LearningabstractIn federated learning (FL), a set of participants share updates computed on their local data with an aggregator server that combines updates into a global model. However, reconciling accuracy with privacy and security is a challenge to FL. On the one hand, good updates sent by honest participants may reveal their private local information, whereas poisoned updates sent by malicious participants may compromise the model's availability and/or integrity. On the other hand, enhancing privacy via update distortion damages accuracy, whereas doing so via update aggregation damages security because it does not allow the server to filter out individual poisoned updates. To tackle the accuracy-privacy-security conflict, we propose fragmented FL (FFL), in which participants randomly exchange and mix fragments of their updates before sending them to the server. To achieve privacy, we design a lightweight protocol that allows participants to privately exchange and mix encrypted fragments of their updates so that the server can neither obtain individual updates nor link them to their originators. To achieve security, we design a reputation-based defense tailored for FFL that builds trust in participants and their mixed updates based on the quality of the fragments they exchange and the mixed updates they send. Since the exchanged fragments' parameters keep their original coordinates and attackers can be neutralized, the server can correctly reconstruct a global model from the received mixed updates without accuracy loss. Experiments on four real data sets show that FFL can prevent semi-honest servers from mounting privacy attacks, can effectively counter-poisoning attacks, and can keep the accuracy of the global model. Najeeb Jebreel, Josep Domingo-Ferrer, Alberto Blanco-Justicia, David Sánchez 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2023 | Secure, accurate and privacy-aware fully decentralized learning via co-utilityabstractFully decentralized learning is a setting in which each peer in a P2P network trains a machine learning model with the help of the other peers. Each peer acts as a model manager by periodically sending her current model to other peers, who answer by returning model updates they compute on their private data. This creates a tension among privacy, accuracy and security. The privacy risk is that model updates returned by a peer can leak some of the peer’s private data. Unfortunately, distorting model updates to protect privacy works against the accuracy of the trained model. On the other hand, aggregating the updates of several peers and then sending the aggregate to the model manager may preserve privacy but it goes against security, because the model manager cannot filter out individual bad updates. Also, peers are autonomous and hence it cannot be taken for granted that they will honestly supply model updates to help the model manager train her model. To reconcile accuracy, privacy and security, we present a fully decentralized learning protocol such that: (i) it allows perfectly accurate individual updates to be returned by peers to the model manager in a privacy-preserving manner; (ii) it is co-utile by design, that is, it incentivizes rational peers to follow the protocol without deviating. The latter feature discourages rational attacks that might compromise security and it also deters free riding, thereby ensuring the sustainability of the protocol. Jesús A. Manjón, Josep Domingo-Ferrer, David Sánchez 0001, Alberto Blanco-Justicia |
Comput. Commun. | 4 |
| 2023 | Fair detection of poisoning attacks in federated learning on non-i.i.d. data
Ashneet Khandpur Singh, Alberto Blanco-Justicia, Josep Domingo-Ferrer |
Data Min. Knowl. Discov. | 2 |
| 2022 | Generation of Synthetic Trajectory Microdata from Language Models
Alberto Blanco-Justicia, Najeeb Jebreel, Jesús A. Manjón, Josep Domingo-Ferrer |
PSD | 1 |
| 2022 | Secure and Privacy-Preserving Federated Learning via Co-UtilityabstractThe decentralized nature of federated learning, that often leverages the power of edge devices, makes it vulnerable to attacks against privacy and security. The privacy risk for a peer is that the model update she computes on her private data may, when sent to the model manager, leak information on those private data. Even more obvious are security attacks, whereby one or several malicious peers return wrong model updates in order to disrupt the learning process and lead to a wrong model being learned. In this article, we build a federated learning framework that offers privacy to the participating peers as well as security against the Byzantine and poisoning attacks. Our framework consists of several protocols that provide strong privacy to the participating peers via unlinkable anonymity and that are rationally sustainable based on the co-utility property. In other words, no rational party is interested in deviating from the proposed protocols. We leverage the notion of co-utility to build a decentralized co-utile reputation management system that provides incentives for parties to adhere to the protocols. Unlike privacy protection via differential privacy, our approach preserves the values of model updates and, hence, the accuracy of plain federated learning; unlike privacy protection via update aggregation, our approach preserves the ability to detect bad model updates while substantially reducing the computational overhead compared to methods based on homomorphic encryption. Josep Domingo-Ferrer, Alberto Blanco-Justicia, Jesús A. Manjón, David Sánchez 0001 |
IEEE Internet Things J. | 2 |
| 2021 | Towards Machine Learning-Assisted Output Checking for Statistical Disclosure Control
Josep Domingo-Ferrer, Alberto Blanco-Justicia |
MDAI | 2 |
| 2021 | Achieving security and privacy in federated learning systems: Survey, research challenges and future directionsabstractFederated learning (FL) allows a server to learn a machine learning (ML) model across multiple decentralized clients that privately store their own training data. In contrast with centralized ML approaches, FL saves computation to the server and does not require the clients to outsource their private data to the server. However, FL is not free of issues. On the one hand, the model updates sent by the clients at each training epoch might leak information on the clients’ private data. On the other hand, the model learnt by the server may be subjected to attacks by malicious clients; these security attacks might poison the model or prevent it from converging. In this paper, we first examine security and privacy attacks to FL and critically survey solutions proposed in the literature to mitigate each attack. Afterwards, we discuss the difficulty of simultaneously achieving security and privacy protection. Finally, we sketch ways to tackle this open problem and attain both security and privacy. Alberto Blanco-Justicia, Josep Domingo-Ferrer, Sergio Martínez, David Sánchez 0001, Adrian Flanagan, Kuan Eeik Tan |
Eng. Appl. Artif. Intell. | 1 |
| 2020 | Co-Utile Peer-to-Peer Decentralized ComputingabstractOutsourcing computation allows wielding huge computational power. Even though cloud computing is the most usual type of outsourcing, resorting to idle edge devices for decentralized computation is an increasingly attractive alternative. We tackle the problem of making peer honesty and thus computation correctness self-enforcing in decentralized computing with untrusted peers. To do so, we leverage the co-utility property, which characterizes a situation in which honest co-operation is the best rational option to take even for purely selfish agents; in particular, if a protocol is co-utile, it is self-enforcing. Reputation is a powerful incentive that can make a P2P protocol co-utile. We present a co-utile P2P decentralized computing protocol that builds on a decentralized reputation calculation, which is itself co-utile and therefore self-enforcing. In this protocol, peers are given a computational task including code and data and they are incentivized to compute it correctly. Based also on co-utile reputation, we then present a protocol for federated learning, whereby peers compute on their local private data and have no incentive to randomly attack or poison the model. Our experiments show the viability of our co-utile approach to obtain correct results in both decentralized computation and federated learning. Josep Domingo-Ferrer, Alberto Blanco-Justicia, David Sánchez 0001, Najeeb Jebreel |
CCGRID | 2 |
| 2020 | Fair Detection of Poisoning Attacks in Federated LearningabstractFederated learning is a decentralized machine learning technique that aggregates partial models trained by a set of clients on their own private data to obtain a global model. This technique is vulnerable to security attacks, such as model poisoning, whereby malicious clients submit bad updates in order to prevent the model from converging or to introduce artificial bias in the classification. Applying anti-poisoning techniques might lead to the discrimination of minority groups whose data are significantly and legitimately different from those of the majority of clients. In this work, we strive to strike a balance between fighting poisoning and accommodating diversity to help learning fairer and less discriminatory federated learning models. In this way, we forestall the exclusion of diverse clients while still ensuring detection of poisoning attacks. Empirical work on a standard machine learning data set shows that employing our approach to tell legitimate from malicious updates produces models that are more accurate than those obtained with standard poisoning detection techniques. Ashneet Khandpur Singh, Alberto Blanco-Justicia, Josep Domingo-Ferrer, David Sánchez 0001, David Rebollo-Monedero |
ICTAI | 2 |
| 2020 | Privacy-Preserving Computation of the Earth Mover's Distance
Alberto Blanco-Justicia, Josep Domingo-Ferrer |
ISC | 1 |
| 2020 | Efficient Detection of Byzantine Attacks in Federated Learning Using Last Layer Biases
Najeeb Jebreel, Alberto Blanco-Justicia, David Sánchez 0001, Josep Domingo-Ferrer |
MDAI | 2 |
| 2020 | Detecting Bad Answers in Survey Data Through Unsupervised Machine Learning
Najeeb Jebreel, Rami Haffar, Ashneet Khandpur Singh, David Sánchez 0001, Josep Domingo-Ferrer, Alberto Blanco-Justicia |
PSD | 6 |
| 2020 | Machine learning explainability via microaggregation and shallow decision trees
Alberto Blanco-Justicia, Josep Domingo-Ferrer, Sergio Martínez, David Sánchez 0001 |
Knowl. Based Syst. | 1 |
| 2019 | Machine Learning Explainability Through Comprehensible Decision Trees
Alberto Blanco-Justicia, Josep Domingo-Ferrer |
CD-MAKE | 1 |
| 2018 | Efficient privacy-preserving implicit authentication
Alberto Blanco-Justicia, Josep Domingo-Ferrer |
Comput. Commun. | 1 |
| 2016 | Privacy-aware loyalty programs
Alberto Blanco-Justicia, Josep Domingo-Ferrer |
Comput. Commun. | 1 |
| 2015 | Flexible and Robust Privacy-Preserving Implicit Authentication
Josep Domingo-Ferrer, Qianhong Wu, Alberto Blanco-Justicia |
SEC | 3 |
| 2014 | Distance Computation between Two Private Preference Functions
Alberto Blanco-Justicia, Josep Domingo-Ferrer, Oriol Farràs, David Sánchez 0001 |
SEC | 1 |