EDBT 2026 Demo / reviewers in the wild / expert
João S. Resende
dblp:183/9115
· DBLP profile ↗
11ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-0125-4240ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RunPBA - Runtime attestation for microcontrollers with PACBTIabstractThe widespread adoption of embedded systems has led to their deployment in critical real-world applications, making them attractive targets for malicious actors. This paper presents RunPBA , a hardware-based runtime attestation system designed to defend against control flow attacks while maintaining minimal performance overhead and adhering to strict power consumption constraints. RunPBA leverages Pointer Authentication and Branch Target Identification (PACBTI), a new processor extension tailored for the ARM Cortex M processor family, allowing robust protection without requiring hardware modifications, a limitation present in similar solutions. We implemented a proof-of-concept and evaluated it using two benchmark suites, Coremark PRO and BEEBS. Experimental results indicate that RunPBA imposes a geometric mean performance overhead of only 1.3% and 6.8% across the benchmarks, underscoring its efficiency and suitability for real-world deployment. André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes |
Comput. Secur. | 3 |
| 2026 | Obscura: Enabling Ephemeral Proxies for Traffic Encapsulation in WebRTC Media Streams Against Cost-Effective CensorsabstractRecent research on online censorship has provided valuable insights into common censorship strategies and censors' tolerance for collateral damage. A consistent finding across these studies is that censors tend to favour cost-effective techniques such as proxy enumeration, active probing, and deep packet inspection (DPI), rather than more complex and non-deterministic methods such as deep learning-based traffic analysis. For example, a recent study on the Snowflake censorship evasion system reinforced this finding by demonstrating that authoritarian regimes primarily relied on DPI to target the system. However, as censorship techniques continue to evolve, two critical questions arise: (1) What future attack vectors are likely to emerge based on current research and observed censor capabilities? (2) How can these emerging threats, along with previously utilised censorship methods, be effectively mitigated? In this paper, we present Obscura, a censorship evasion system designed to resist cost-effective, historically grounded censorship techniques while also defending against a class of plausible future attacks within a cost-effective threat model targeting WebRTC-based censorship evasion systems. Obscura is built upon four core features: (1) encapsulation of traffic within WebRTC media streams, (2) the use of a reliability layer, (3) support for both browser-based and Pion-based clients and proxy instances, and (4) the use of ephemeral proxies. Each feature is intended to mitigate either a known attack observed in the wild or a theoretically plausible attack consistent with the capabilities of a cost-effective censor. We provide a security analysis to justify our design choices and a performance evaluation to demonstrate that Obscura maintains reasonable throughput for typical online activities. João Afonso Vilalonga, Kevin Gallagher 0001, João S. Resende, Henrique Domingos |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Online Influence Forest for Streaming Anomaly Detection
Inês Martins, João S. Resende, João Gama 0001 |
IDA | 2 |
| 2023 | TorKameleon: Improving Tor's Censorship Resistance with K-anonymization and Media-based Covert ChannelsabstractAnonymity networks like Tor significantly enhance online privacy but are vulnerable to correlation attacks by state-level adversaries. While covert channels encapsulated in media protocols, particularly WebRTC-based encapsulation, have demonstrated effectiveness against passive traffic correlation attacks, their resilience against active correlation attacks remains unexplored, and their compatibility with Tor has been limited. This paper introduces TorKameleon, a censorship evasion solution designed to protect Tor users from both passive and active correlation attacks. TorKameleon employs K-anonymization techniques to fragment and reroute traffic through multiple TorKameleon proxies, while also utilizing covert WebRTC-based channels or TLS tunnels to encapsulate user traffic. João Afonso Vilalonga, João S. Resende, Henrique Domingos |
TrustCom | 2 |
| 2022 | Threat Detection and Mitigation with Honeypots: A Modular Approach for IoT
Simão Silva, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes |
TrustBus | 3 |
| 2022 | IoT security certifications: Challenges and potential approaches
André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes |
Comput. Secur. | 3 |
| 2022 | Host-based IDS: A review and open issues of an anomaly detection system in IoT
Inês Martins, João S. Resende, Patrícia R. Sousa, Simão Silva, Luis Filipe Coelho Antunes, João Gama 0001 |
Future Gener. Comput. Syst. | 2 |
| 2021 | Hardening cryptographic operations through the use of secure enclaves
André Brandão, João S. Resende, Rolando Martins |
Comput. Secur. | 2 |
| 2020 | Employment of Secure Enclaves in Cheat Detection Hardening
André Brandão, João S. Resende, Rolando Martins |
TrustBus | 2 |
| 2018 | Enforcing Privacy and Security in Public Cloud StorageabstractCloud storage allows users to remotely store their data, giving access anywhere and to anyone with an Internet connection. The accessibility, lack of local data maintenance and absence of local storage hardware are the main advantages of this type of storage. The adoption of this type of storage is being driven by its accessibility. However, one of the main barriers to its widespread adoption is the sovereignty issues originated by lack of trust in storing private and sensitive information in such a medium. Recent attacks to cloud-based storage show that current solutions do not provide adequate levels of security and subsequently fail to protect users' privacy. Usually, users rely solely on the security supplied by the storage providers, which in the presence of a security breach will ultimate lead to data leakage. In this paper, we propose and implement a broker (ARGUS) that acts as a proxy to the existing public cloud infrastructures by performing all the necessary authentication, cryptography and erasure coding. ARGUS uses erasure code as a way to provide efficient redundancy (opposite to standard replication) while adding an extra layer to data protection in which data is broken into fragments, expanded and encoded with redundant data pieces that are stored across a set of different storage providers (public or private). The key characteristics of ARGUS are confidentiality, integrity and availability of data stored in public cloud systems. João S. Resende, Rolando Martins, Luis Filipe Coelho Antunes |
PST | 1 |
| 2018 | Evaluating the Privacy Properties of Secure VoIP Metadata
João S. Resende, Patrícia R. Sousa, Luis Filipe Coelho Antunes |
TrustBus | 1 |