EDBT 2026 Demo / reviewers in the wild / expert
Bernardo Ferreira
dblp:145/9850
· DBLP profile ↗
16ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-6956-0968ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 5 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MVP-ORAM: a Wait-free Concurrent ORAM for Confidential BFT Storage
Robin Vassantlal, Hasan Heydari, Bernardo Ferreira, Alysson Neves Bessani |
NDSS | 3 |
| 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code PrivacyabstractSoftware vulnerabilities continue to be the primary cause of cyberattacks. It is crucial to identify vulnerabilities in applications' source code before attackers gain access to them and exploit any vulnerability they may contain. Developers have used static analysis tools (SATs) to find vulnerabilities in unprotected application code, and software testing companies have started offering software code analysis as a service to assist developers in these findings. Such services require access to unprotected code, which raises concerns about its privacy and intellectual property theft. Attackers can also perform this analysis using similar tools, if they gain access to the code. It is, therefore, beneficial to have a system that can maintain code privacy by protecting it with cryptographic techniques, while still allowing authorised people to detect vulnerabilities in the encrypted code. This paper presents such a solution, a novel approach to Software Quality and Privacy that allows source code to be analysed in a protected manner, preserving its privacy. The proposed solution combines Static Analysis with Searchable Symmetric Encryption (SSE) for confidential vulnerability detection, enabling data and dependency tracking for data flow analysis over encrypted source code. The solution represents the code's data and control flows as an Encrypted Inverted Index, in a connected way that enables SSE's queries for vulnerability discovery. The solution was implemented as the CoCoA tool and evaluated with synthetic and real PHP web applications. Results show that CoCoA has similar precision as (non-confidential) SATs - 93% - with real applications, requiring only 209 ms to process 4k LoC - a modest overhead of 42.7% compared to a non-confidential baseline. This paper also defines a new research field - Confidential Code Analysis -, from which other types of code analysis tasks can be derived. David Dantas, Rafael Ramires, Bernardo Ferreira, Iberia Medeiros |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | SoK: Self-Generated Nudes over Private Chats: How can Technology Contribute to a Safer Sexting?abstractMore and more people take advantage of mobile apps to strike up relationships and casual contacts. This sometimes results in the sharing of self-generated nudes. While this opens a way for sexual exploration, it also raises concerns. In this paper, we review existing technology-assisted permissive proposals/features that provide security, privacy or accountability benefits when sharing nudes online. To do so, we performed a systematic literature review combing through 10,026 search results and cross-references, and we identified real-world solutions by surveying OS features and 52 dating, messaging and social network apps. We systematized knowledge by defining a sexting threat model, deriving a taxonomy of the proposals/features, discussing some of their shortcomings, organizing privacy-related concepts, and providing take-aways with some directions for future research and development. Our study found a very diverse ecosystem of academic proposals and app features, showing that safer sexting goes far beyond nude detection. None of the techniques represents the ultimate solution for all threats, but each contributes to a safer sexting in a different way. Joel Samper, Bernardo Ferreira |
SP | 2 |
| 2024 | Co-Development of a Serious Game for Social Skills Training for patients with Acquired Brain InjuryabstractAcquired brain injury (ABI) is a condition that causes damage to brain tissues and consequently leads to physical, behavioral and cognitive issues. One of the impairments observed after the injury is in the realm of social cognition (SC). This impairment leads these patients to lose their ability to interact socially in a positive and effective manner. Consequently, these patients may socially isolate themselves and lose interpersonal relationships. One of the methods used for cognitive rehabilitation that has proven to be effective is the use of serious games (SG). SG are video games with the purpose of learning and improving people’s live. Thus, in this work, a set of SG will be developed for the cognitive and psychosocial rehabilitation of people with ABI, focusing on socio-emotional skills training. To ensure their success, a co-design methodology will be carried out during the conception and implementation of the game. This approach will involve patients, healthcare professionals, and caregivers to obtain suggestions and feedback to ensure that the most suitable solutions are implemented in the game. At the end of this work, we hope to have developed a method for training socio-emotional skills that can motivate patients more effectively than traditional methods. Bernardo Ferreira, Simão Reis, Luís Paulo Reis, Marta Pereira, Eliana Silva |
CoG | 1 |
| 2024 | P4chaskey: an Efficient Mac Algorithm for Pisa SwitchesabstractCryptographic primitives are of paramount importance to guarantee security properties in communication networks. The associated computational complexity of cryptography standards makes it prohibitive to execute these primitives at line rate in the network core. Existing implementations of cryptographic MAC algorithms in$\mathbf{P 4}$for programmable switches impose a severe performance penalty due to packet recirculation, which may not be tolerable at those network speeds. In this paper, we propose the first data plane design in$\mathbf{P 4}$of the Chaskey algorithm, a widely used secure and lightweight cryptographic MAC algorithm, tailored for the PISA switch architecture. Our P4Chaskey is the first solution to compute MACs using 128-bit keys without packet recirculation, guaranteeing line rate Terabit speeds. As state-of-the-art solutions require recirculations for the same key size (reducing throughput performance) or offer weaker security (smaller keys), P4CHASKEY is now, to our knowledge, the most efficient MAC design for the target switch architecture. Martim Francisco, Bernardo Ferreira, Fernando M. V. Ramos, Eduard Marin, Salvatore Signorello |
ICNP | 2 |
| 2024 | Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset Sum
Daniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro 0004, Diogo Barradas, Bernardo Portela, João Vinagre, Bernardo Ferreira, Nicolas Christin, Nuno Santos 0001 |
NDSS | 8 |
| 2023 | Code Privacy in Detection of Web VulnerabilitiesabstractWe propose a solution combining source code static analysis with searchable symmetric encryption to detect input validation vulnerabilities of web applications in encrypted PHP code, allowing developers to protect their codebase from malicious third parties while simultaneously discovering vulnerabilities in it. Results show that our solution is capable of identifying vulnerabilities with precision similar to traditional static code, non-privacy-preserving analysers and exhibits a maximum overhead increase of around 16,55%. Iberia Medeiros, Bernardo Ferreira |
EASE | 3 |
| 2022 | Poster: User Sessions on Tor Onion Services: Can Colluding ISPs Deanonymize Them at Scale?abstractTor is the most popular anonymity network in the world. It relies on advanced security and obfuscation techniques to ensure the privacy of its users and free access to the Internet. However, the investigation of traffic correlation attacks against Tor Onion Services (OSes) has been relatively overlooked in the literature. In particular, determining whether it is possible to emulate a global passive adversary capable of deanonymizing the IP addresses of both the Tor OSes and of the clients accessing them has remained, so far, an open question. In this paper, we present ongoing work toward addressing this question and reveal some preliminary results on a scalable traffic correlation attack that can potentially be used to deanonymize Tor OS sessions. Our attack is based on a distributed architecture involving a group of colluding ISPs from across the world. After collecting Tor traffic samples at multiple vantage points, ISPs can run them through a pipeline where several stages of traffic classifiers employ complementary techniques that result in the deanonymization of OS sessions with high confidence (i.e., low false positives). We have responsibly disclosed our early results with the Tor Project team and are currently working not only on improving the effectiveness of our attack but also on developing countermeasures to preserve Tor users' privacy. Daniela Lopes, Pedro Medeiros, Jin-Dong Dong, Diogo Barradas, Bernardo Portela, João Vinagre, Bernardo Ferreira, Nicolas Christin, Nuno Santos 0001 |
CCS | 7 |
| 2022 | COBRA: Dynamic Proactive Secret Sharing for Confidential BFT ServicesabstractByzantine Fault-Tolerant (BFT) State Machine Replication (SMR) is a classical paradigm for implementing trustworthy services that has received renewed interest with the emergence of blockchains and decentralized infrastructures. A fundamental limitation of BFT SMR is that it provides integrity and availability despite a fraction of the replicas being controlled by an active adversary, but does not offer any confidentiality protection. Previous works addressed this issue by integrating secret sharing with the consensus-based framework of BFT SMR, but without providing all features required by practical systems, which include replica recovery, group reconfiguration, and acceptable performance when dealing with a large number of secrets. We present COBRA, a new protocol stack for Dynamic Proactive Secret Sharing that allows implementing confidentiality in practical BFT SMR systems. COBRA exhibits the best asymptotic communication complexity and optimal storage overhead, being able to renew 100k shares in a group of ten replicas $5 \times $ faster than the current state of the art. Robin Vassantlal, Eduardo Alchieri, Bernardo Ferreira, Alysson Neves Bessani |
SP | 3 |
| 2022 | Boolean Searchable Symmetric Encryption With Filters on Trusted HardwareabstractThe prevalence and availability of cloud infrastructures has made them thede factosolution for storing and archiving data, both for organizations and individual users. Nonetheless, the cloud’s wide spread adoption is still hindered by dependability and security concerns, particularly in applications with large data collections where efficient search and retrieval services are also major requirements. This leads to an increased tension between security, efficiency, and search expressiveness. In this article we tackle this tension by proposing BISEN, a new provably-secure boolean searchable symmetric encryption scheme that improves these three complementary dimensions by exploring the design space of isolation guarantees offered by novel commodity hardware such as Intel SGX, abstracted as Isolated Execution Environments (IEEs). BISEN is the first scheme to support multiple users and enable highly expressive and arbitrarily complex boolean queries, with minimal information leakage regarding performed queries and accessed data, and verifiability regarding fully malicious adversaries. Furthermore, BISEN extends the traditional SSE model to support filter functions on search results based on generic metadata created by the users. Experimental validation and comparison with the state of art shows that BISEN provides better performance with enriched search semantics and security properties. Bernardo Ferreira, Bernardo Portela, Tiago Oliveira 0004, Guilherme Borges, Henrique João L. Domingos, João Leitão 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | SLICER: Safe Long-Term Cloud Event ArchivalabstractSecurity Information and Event Management (SIEM) systems have been adopted by organizations to enable holistic monitoring of malicious activities in their IT infrastructures. SIEMs receive events from several devices of the organization's IT infrastructure (e.g., servers, firewalls, IDS), correlate these events, and present reports for security analysts. Given the large number of events collected by SIEMs, it is costly to store such data for long periods. Besides, since organizations store a relatively limited time-frame of events, the forensic analysis capabilities severely become reduced. We present SL I CER an archival system for long-term storage that makes use of multi-cloud storage to guarantee data security, low cost and high scalability, and ensures cost-effectiveness by grouping events in blocks and using indexing techniques to recover them. The system was evaluated using a real dataset, and the results show that it is significantly more cost-efficient than competing alternatives. Adriano Serckumecka, Iberia Medeiros, Bernardo Ferreira, Alysson Neves Bessani |
PRDC | 3 |
| 2019 | BISEN: Efficient Boolean Searchable Symmetric Encryption with Verifiability and Minimal LeakageabstractThe prevalence and availability of cloud infrastructures has made them the de facto solution for storing and archiving data, both for organizations and individual users. Nonetheless, the cloud's wide spread adoption is still hindered by dependability and security concerns, particularly in applications with large data collections where efficient search and retrieval services are also major requirements. This leads to an increased tension between security, efficiency, and search expressiveness, which current state of the art solutions try to balance through complex cryptographic protocols that tradeoff efficiency and expressiveness for near optimal security. In this paper we tackle this tension by proposing BISEN, a new provably-secure boolean searchable symmetric encryption scheme that improves these three complementary dimensions by exploring the design space of isolation guarantees offered by novel commodity hardware such as Intel SGX, abstracted as Isolated Execution Environments (IEEs). BISEN is the first scheme to enable highly expressive and arbitrarily complex boolean queries, with minimal information leakage regarding performed queries and accessed data, and verifiability regarding fully malicious adversaries. Furthermore, by exploiting trusted hardware and the IEE abstraction, BISEN reduces communication costs between the client and the cloud, boosting query execution performance. Experimental validation and comparison with the state of art shows that BISEN provides better performance with enriched search semantics and security properties. Bernardo Ferreira, Bernardo Portela, Tiago Oliveira 0004, Guilherme Borges, Henrique João L. Domingos, João Leitão 0001 |
SRDS | 1 |
| 2019 | Practical Privacy-Preserving Content-Based Retrieval in Cloud Image RepositoriesabstractStorage requirements for visual data have been increasing in recent years, following the emergence of many highly interactive multimedia services and applications for mobile devices in both personal and corporate scenarios. This has been a key driving factor for the adoption of cloud-based data outsourcing solutions. However, outsourcing data storage to the Cloud also leads to new security challenges that must be carefully addressed, especially regarding privacy. In this paper we propose a secure framework for outsourced privacy-preserving storage and retrieval in large shared image repositories. Our proposal is based on IES-CBIR, a novel Image Encryption Scheme that exhibits Content-Based Image Retrieval properties. The framework enables both encrypted storage and searching using Content-Based Image Retrieval queries while preserving privacy against honest-but-curious cloud administrators. We have built a prototype of the proposed framework, formally analyzed and proven its security properties, and experimentally evaluated its performance and retrieval precision. Our results show that IES-CBIR is provably secure, allows more efficient operations than existing proposals, both in terms of time and space complexity, and paves the way for new practical application scenarios. Bernardo Ferreira, João Rodrigues 0004, João Leitão 0001, Henrique João L. Domingos |
IEEE Trans. Cloud Comput. | 1 |
| 2018 | MuSE: Multimodal Searchable Encryption for Cloud ApplicationsabstractIn this paper we tackle the practical challenges of searching encrypted multimodal data (i.e., data containing multiple media formats simultaneously), stored in public cloud servers, with reduced information leakage. To this end we propose MuSE, a Multimodal Searchable Encryption scheme that, by combining only standard cryptographic primitives and symmetric-key block ciphers, allows cloud-backed applications to dynamically store, update, and search multimodal datasets with privacy and efficiency guarantees. As searching encrypted data requires a tradeoff between privacy and efficiency, we also propose a variant of MuSE that resorts to partially homomorphic encryption to further reduce information leakage, but at the cost of additional computational overhead. Both schemes are formally proven secure and experimentally evaluated regarding performance and search precision. Experiments with realistic datasets show that our contributions achieve interesting levels of efficiency and privacy, making MuSE particularly suitable for practical application scenarios. Bernardo Ferreira, João Leitão 0001, Henrique João L. Domingos |
SRDS | 1 |
| 2017 | Multimodal Indexable Encryption for Mobile Cloud-Based ApplicationsabstractIn this paper we propose MIE, a Multimodal Indexable Encryption framework that for the first time allows mobile applications to securely outsource the storage and search of their multimodal data (i.e. data containing multiple media formats) to public clouds with privacy guarantees. MIE is designed as a distributed framework architecture, leveraging on shared cloud repositories that can be accessed simultaneously by multiple users. At its core MIE relies on Distance Preserving Encodings (DPE), a novel family of encoding algorithms with cryptographic properties that we also propose. By applying DPE to multimodal data features, MIE enables high-cost clustering and indexing operations to be handled by cloud servers in a privacy-preserving way. Experiments show that MIE achieves better performance and scalability when compared with the state of art, with measurable impact on mobile resources and battery life. Bernardo Ferreira, João Leitão 0001, Henrique João L. Domingos |
DSN | 1 |
| 2015 | Privacy-Preserving Content-Based Image Retrieval in the CloudabstractStorage requirements for visual data have been increasing in recent years, following the emergence of many new highly interactive multimedia services and applications for both personal and corporate use. This has been a key driving factor for the adoption of cloud-based data outsourcing solutions. However, outsourcing data storage to the Cloud also leads to new challenges that must be carefully addressed, especially regarding privacy. In this paper we propose a secure framework for outsourced privacy-preserving storage and retrieval in large image repositories. Our proposal is based on IES-CBIR, a novel Image Encryption Scheme that displays Content-Based Image Retrieval properties. Our solution enables both encrypted storage and searching using CBIR queries while preserving privacy. We have built a prototype of the proposed framework, formally analyzed and proven its security properties, and experimentally evaluated its performance and precision. Our results show that IES-CBIR is provably secure, allows more efficient operations than existing proposals, both in terms of time and space complexity, and enables more reliable practical application scenarios. Bernardo Ferreira, João Rodrigues 0004, João Leitão 0001, Henrique João L. Domingos |
SRDS | 1 |