EDBT 2026 Demo / reviewers in the wild / expert
José M. del Álamo
dblp:15/5001
· DBLP profile ↗
9ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0002-6513-0303ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy Settings of Third-Party Libraries in Android Apps: A Study of Facebook SDKsabstractPrevious studies have demonstrated that privacy issues in mobile apps often stem from the integration of third-party libraries (TPLs). To shed light on factors that contribute to these issues, we investigate the privacy-related configuration choices available to and made by Android app developers who incorporate the Facebook Android SDK and Facebook Audience Network SDK in their apps. We compile these Facebook SDKs' privacy-related settings and their defaults. Employing a multi-method approach that integrates static and dynamic analysis, we analyze more than 6,000 popular apps to determine whether the apps incorporate Facebook SDKs and, if so, whether and how developers modify settings. Finally, we assess how these settings align with the privacy practices that developers disclose in the apps’ privacy labels and policies. We observe widespread inconsistencies between practices and disclosures in popular apps. These inconsistencies often stem from privacy settings, including a substantial number of cases in which apps retain default settings over alternatives that offer greater privacy. We observe fewer possible compliance issues in potentially child-directed apps, but issues persist even in these apps. We discuss remediation strategies that SDK and TPL providers could employ to help developers, particularly developers with fewer resources who rely heavily on SDKs. Our recommendations include aligning default privacy settings with data minimization principles and other conservative practices and making privacy-related SDK information both easier to find and harder to miss. David Rodríguez Torrado, Joseph A. Calandrino, José M. del Álamo, Norman M. Sadeh |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Hunter: Tracing anycast communications to uncover cross-border personal data transfersabstractCross-border personal data transfers are heavily regulated worldwide, with data protection authorities imposing huge fines on organizations that fail to meet their strict compliance requirements. However, network-level optimizations such as anycast addresses were not designed with personal data in mind, and their use may unwittingly divert personal data out of a legal boundary. This paper describes Hunter, an automated method to trace anycast communications and identify those threatening data protection compliance. We have applied Hunter in the wild to a set of Android apps to discover that all apps observed sending personal data to anycast addresses eventually carry out international transfers but fail to disclose them in their privacy policies. Our findings suggest that using anycast addresses to transmit personal data generally results in data protection compliance issues. Hugo Pascual, José M. del Álamo, David Rodríguez Torrado, Juan C. Dueñas |
Comput. Secur. | 2 |
| 2023 | A formal model for reliable digital transformation of water distribution networksabstractThe concept of modernizing outdated systems in critical infrastructure through digital transformation has been a widely discussed topic nowadays. Following the transition of energy systems, the attention has now shifted towards digitalizing the water distribution systems. These systems are large-scale but outdated systems that frequently encounter various issues and upgrading them would enable easier to identify issues and provide smoother, more efficient service. However, this process requires cautious planning and guidance to ensure that the generated data is reliable, and the system remains operational during the transition. Hence, the primary objective of this paper is to propose a formal model based on ternary relational semantics that can guide the digital transformation of water distribution networks. The proposed model provides a flexible transformation process while making the system generate reliable data. Additionally, this paper demonstrates the application of the proposed model by developing a proof of concept based on a real-world scenario. José Miguel Blanco 0002, Mouzhi Ge, José M. del Álamo, Juan C. Dueñas, Félix Cuadrado |
KES | 3 |
| 2023 | Automated GDPR compliance assessment for cross-border personal data transfers in android applicationsabstractThe General Data Protection Regulation (GDPR) aims to ensure that all personal data processing activities are fair and transparent for the European Union (EU) citizens, regardless of whether these are carried out within the EU or anywhere else. To this end, it sets strict requirements to transfer personal data outside the EU. However, checking these requirements is a daunting task for supervisory authorities, particularly in the mobile app domain due to the huge number of apps available and their dynamic nature. In this paper, we propose a fully automated method for assessing the compliance of Android apps with the GDPR requirements for cross-border personal data transfers. We have applied the method to 4593 apps from the Google Play Store discovering that nearly half of the ones sending personal data are potentially non-compliant with GDPR requirements. These results reveal that there is still a very significant gap between what app providers do in practice and what is intended by the GDPR. Danny S. Guamán, David Rodríguez Torrado, José M. del Álamo, Jose M. Such |
Comput. Secur. | 3 |
| 2023 | Enhancing Web Applications Observability through Instrumented Automated BrowsersabstractIn software engineering, observability is the ability to determine the current state of a software system based on its external outputs or signals such as metrics, logs, or traces. Web engineers rely on the web browser console as the primary tool to monitor the client-side of web applications during end-to-end tests. However, this is a manual and time-consuming task due to the different browsers available. This paper presents BrowserWatcher, an open-source browser extension providing cross-browser capabilities to observe web applications and automatically gather browser console logs in different browsers (e.g., Chrome, Firefox, or Edge). We have leveraged this extension to conduct an empirical study analyzing the browser console of the top-50 public websites manually and automatically. The results show that BrowserWatcher gathers all the well-known log categories such as console or error traces. It also reveals that each web browser additionally includes other types of logs, which differ among browsers, thus providing distinct pieces of information for the same website. Boni García, Filippo Ricca, José M. del Álamo, Maurizio Leotta |
J. Syst. Softw. | 3 |
| 2022 | Identifying Organizations Receiving Personal Data in Android Apps
David Rodríguez Torrado, Miguel Cozar, José M. del Álamo |
SECRYPT | 3 |
| 2011 | A user-centric approach to service creation and delivery over next generation networks
Juan C. Yelmo, José M. del Álamo, Rubén Trapero, Yod Samuel Martín |
Comput. Commun. | 2 |
| 2011 | A Privacy-Considerate Framework for Identity Management in Mobile Services
José M. del Álamo, Antonio M. Fernández, Rubén Trapero, Juan C. Yelmo, Miguel-Ángel Monjas |
Mob. Networks Appl. | 1 |
| 2007 | User-Driven Service Lifecycle Management - Adopting Internet Paradigms in Telecom Services
Juan C. Yelmo, Rubén Trapero, José M. del Álamo, Jürgen Sienel, Marc Drewniok, Isabel Ordás, Kathleen McCallum |
ICSOC | 3 |