EDBT 2026 Demo / reviewers in the wild / expert
Jose Luis Flores 0001
dblp:21/5415 · also Jose Luis Flores Barroso
· DBLP profile ↗
14ranked-venue papers
4as first author
11since 2021 · last 2025
0000-0002-5555-9712ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 7 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 1 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Sow Smarter, Not Harder: Evaluating LLM-Generated Seeds for Fuzzing Critical Infrastructure
Jorge Barredo, Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
CRITIS | 3 |
| 2025 | GJALLARHORN: A framework for vulnerability detection via electromagnetic side-channel analysis in embedded systemsabstractThe proliferation of embedded systems within the Internet of Things (IoT) has heightened the difficulty of detecting vulnerabilities due to their inherent resource constraints. This paper introduces GJALLARHORN, a framework extending electromagnetic side-channel analysis (EM SCA) for early-stage vulnerability detection in embedded systems. Unlike conventional methods requiring code access or imposing computational overhead, GJALLARHORN non-invasively analyses EM emissions to identify anomalous patterns indicating potential security vulnerabilities. By observing hardware-level manifestations of software execution, GJALLARHORN complements software-level analysis, revealing vulnerabilities that might otherwise remain undetected. The framework adapts to device complexity, enabling categorisation of up to 16 distinct vulnerability types, including buffer overflows, memory leaks, and arithmetic errors. Evaluations on both low-end (STM NUCLEO-144) and high-end (Raspberry Pi 3B) architectures demonstrate GJALLARHORN’s effectiveness, achieving a recall of 95.94% and F 1 score of 96.39% on the low-end system, and 73.33% recall with 84.61% F 1 score on the high-end system. Our results reveal that memory-related vulnerabilities produce more distinguishable EM signatures than arithmetic errors, offering valuable insights for externally detecting vulnerabilities. By enabling detection during development, GJALLARHORN helps mitigate risks before deployment, potentially reducing the economic impact of security incidents in IoT infrastructure. Jorge Barredo, Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
Comput. Secur. | 3 |
| 2024 | Gotham Testbed: A Reproducible IoT Testbed for Security Experiments and Dataset GenerationabstractThe growing adoption of the Internet of Things (IoT) has brought a significant increase in attacks targeting those devices. Machine learning (ML) methods have shown promising results for intrusion detection; however, the scarcity of IoT datasets remains a limiting factor in developing ML-based security systems for IoT scenarios. Static datasets get outdated due to evolving IoT architectures and threat landscape; meanwhile, the testbeds used to generate them are rarely published. This paper presents the Gotham testbed, a reproducible and flexible security testbed extendable to accommodate new emulated devices, services or attackers. Gotham is used to build an IoT scenario composed of 100 emulated devices communicating via MQTT, CoAP and RTSP protocols, among others, in a topology composed of 30 switches and 10 routers. The scenario presents three threat actors, including the entire Mirai botnet lifecycle and additional red-teaming tools performing DoS, scanning, and attacks targeting IoT protocols. The testbed has many purposes, including a cyber range, testing security solutions, and capturing network and application data to generate datasets. We hope that researchers can leverage and adapt Gotham to include other devices, state-of-the-art attacks and topologies to share scenarios and datasets that reflect the current IoT settings and threat landscape. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Federated Explainability for Network Anomaly CharacterizationabstractMachine learning (ML) based systems have shown promising results for intrusion detection due to their ability to learn complex patterns. In particular, unsupervised anomaly detection approaches offer practical advantages as does not require labeling the training data, which is costly and time-consuming. To further address practical concerns, there is a rising interest in adopting federated learning (FL) techniques as a recent ML model training paradigm for distributed settings (e.g., IoT), thereby addressing challenges such as data privacy, availability and communication cost concerns. However, output generated by unsupervised models provide limited contextual information to security analysts at SOCs, as they usually lack the means to know why a sample was classified as anomalous or cannot distinguish between different types of anomalies, difficulting the extraction of actionable information and correlation with other indicators. Moreover, ML explainability methods have received little attention in FL settings and present additional challenges due to the distributed nature and data locality requirements. This paper proposes a new methodology to characterize and explain the anomalies detected by unsupervised ML-based intrusion detection models in FL settings. We adapt and develop explainability, clustering and cluster validation algorithms to FL settings to mine patterns in the anomalous samples and identify different threats throughout the entire network, demonstrating the results on two network intrusion detection datasets containing real IoT malware, namely Gafgyt and Mirai, and various attack traces. The learned clustering results can be used to classify emerging anomalies, provide additional context that can be leveraged to gain more insight and enable the correlation of the anomalies with alerts triggered by other security solutions. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
RAID | 2 |
| 2023 | Clustered federated learning architecture for network anomaly detection in large scale heterogeneous IoT networksabstractThere is a growing trend of cyberattacks against Internet of Things (IoT) devices; moreover, the sophistication and motivation of those attacks is increasing. The vast scale of IoT, diverse hardware and software, and being typically placed in uncontrolled environments make traditional IT security mechanisms such as signature-based intrusion detection and prevention systems challenging to integrate. They also struggle to cope with the rapidly evolving IoT threat landscape due to long delays between the analysis and publication of the detection rules. Machine learning methods have shown faster response to emerging threats; however, model training architectures like cloud or edge computing face multiple drawbacks in IoT settings, including network overhead and data isolation arising from the large scale and heterogeneity that characterizes these networks. This work presents an architecture for training unsupervised models for network intrusion detection in large, distributed IoT and Industrial IoT (IIoT) deployments. We leverage Federated Learning (FL) to collaboratively train between peers and reduce isolation and network overhead problems. We build upon it to include an unsupervised device clustering algorithm fully integrated into the FL pipeline to address the heterogeneity issues that arise in FL settings. The architecture is implemented and evaluated using a testbed that includes various emulated IoT/IIoT devices and attackers interacting in a complex network topology comprising 100 emulated devices, 30 switches and 10 routers. The anomaly detection models are evaluated on real attacks performed by the testbed’s threat actors, including the entire Mirai malware lifecycle, an additional botnet based on the Merlin command and control server and other red-teaming tools performing scanning activities and multiple attacks targeting the emulated devices. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
Comput. Secur. | 2 |
| 2023 | Improving fuzzing assessment methods through the analysis of metrics and experimental conditionsabstractFuzzing is nowadays one of the most widely used bug hunting techniques. By automatically generating malformed inputs, fuzzing aims to trigger unwanted behavior on its target. While fuzzing research has matured considerably in the last years, the evaluation and comparison of different fuzzing proposals remain challenging, as no standard set of metrics, data, or experimental conditions exist to allow such observation. This paper aims to fill that gap by proposing a standard set of features to allow such comparison. For that end, it first reviews the existing evaluation methods in the literature and discusses all existing metrics by evaluating seven fuzzers under identical experimental conditions. After examining the obtained results, it recommends a set of practices –particularly on the metrics to be used–, to allow proper comparison between different fuzzing proposals. Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
Comput. Secur. | 2 |
| 2022 | Non-parametric discretization for probabilistic labeled dataabstractProbabilistic label learning is a challenging task that arises from recent real-world problems within the weakly supervised classification framework. In this task algorithms have to deal with datasets where each instance has associated a set of probabilities belonging to different class labels. In this paper, we propose a supervised univariate non-parametric discretization algorithm based on kernel density estimation that can deal with probabilistic labeled data. The algorithm takes advantage of the estimation of the class conditional densities to produce different sets of cut points according to different smoothing parameters of the kernel. Then, the best set of cut points is selected according to a given supervised classification performance measure. The computational complexity is O(NlogN), where N is the number of instances. The proposal is tested on simulated probabilistic labeled data, which allows assessing the behavior with different noise degrees. The results show that the algorithm outperforms other discretization algorithms and is robust to different degrees of uncertainty. Jose Luis Flores 0001, Borja Calvo, Aritz Pérez Martínez |
Pattern Recognit. Lett. | 1 |
| 2022 | Towards Human Dependency Elimination: AI Approach to SCA Robustness AssessmentabstractEvaluating the side-channel resistance in practice is a problematic and arduous process. Current certification schemes require to attack the device under test with an ever-growing number of techniques to validate its security. In addition, the success or failure of these techniques strongly depends on the individual implementing them due to the fallible and human intrinsic nature of several steps of this path. To alleviate this problem, we propose a battery of automated (Estimation of Distribution Algorihm(EDA)-based) attacks as a side-channel analysis robustness assessment of an embedded device. To prove our approach, we conduct realistic experiments on two different devices, creating a new dataset (AES_RA) as a part of our contribution. Furthermore, in this context of automation, we propose several novel improvements over current EDA-based attacks, as follows: 1) optimization of the search process by employing two proposed initialization techniques; 2) improvement and analysis of the generalization of the obtained templates; 3) acceleration of the search process by combining EDAs with Principal Component Analysis (PCA). The last contribution also serves as an alternative way of selecting optimal principal components automatically. We support our claims with experiments on AES_RA and a public dataset (ASCAD), showing how our, although fully automated, approach can straightforwardly provide state-of-the-art results. Unai Rioja, Lejla Batina, Igor Armendariz, Jose Luis Flores 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Optimization Techniques and Formal Verification for the Software Design of Boolean Algebra Based Safety-Critical SystemsabstractArtificial intelligence, and the ability to learn optimized solutions that comply with a set of safety rules, could facilitate the human-based design process of safety-critical systems. However, the reconciliation of state-of-the-art artificial intelligence technology with current safety standards and safety engineering processes is a challenge to be addressed. In this article, this publication describes a method based on optimization and on formal verification for the design of safety-critical systems that are defined by Boolean algebra. Several diverse optimization techniques and a hybrid of these approaches are used to find an optimized design that considers performance requirements, availability rules, and complies with all defined safety rules. Subsequently, this solution is translated into an alternative knowledge representation that can be formally verified and developed in compliance with currently considered safety standards. This method is evaluated with a simplified safety-critical case study. Jon Pérez 0001, Jose Luis Flores 0001, Christian Blum 0001, Jesús Cerquides, Alex Abuin |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | Auto-tune POIs: Estimation of distribution algorithms for efficient side-channel analysisabstract\n Contains fulltext :\n 237439.pdf (Publisher’s version ) (Open Access)\n Unai Rioja, Lejla Batina, Jose Luis Flores 0001, Igor Armendariz |
Comput. Networks | 3 |
| 2021 | Fuzzing the Internet of Things: A Review on the Techniques and Challenges for Efficient Vulnerability Discovery in Embedded SystemsabstractWith a growing number of embedded devices that create, transform, and send data autonomously at its core, the Internet of Things (IoT) is a reality in different sectors, such as manufacturing, healthcare, or transportation. With this expansion, the IoT is becoming more present in critical environments, where security is paramount. Infamous attacks, such as Mirai, have shown the insecurity of the devices that power the IoT, as well as the potential of such large-scale attacks. Therefore, it is important to secure these embedded systems that form the backbone of the IoT. However, the particular nature of these devices and their resource constraints mean that the most cost-effective manner of securing these devices is to secure them before they are deployed, by minimizing the number of vulnerabilities they ship. To this end, fuzzing has proved itself as a valuable technique for automated vulnerability finding, where specially crafted inputs are fed to programs in order to trigger vulnerabilities and crash the system. In this survey, we link the world of embedded IoT devices and fuzzing. For this end, we list the particularities of the embedded world as far as security is concerned, we perform a literature review on fuzzing techniques and proposals, studying their applicability to embedded IoT devices and, finally, we present future research directions by pointing out the gaps identified in the review. Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
IEEE Internet Things J. | 2 |
| 2019 | Supervised non-parametric discretization based on Kernel density estimation
Jose Luis Flores 0001, Borja Calvo, Aritz Pérez Martínez |
Pattern Recognit. Lett. | 1 |
| 2018 | Runtime Vulnerability Discovery as a Service on Industrial Internet of Things (IIoT) SystemsabstractThe IoT and IIoT paradigms are creating new business opportunities. However, high-interconnectivity among all objects introduce new security concerns and challenges. Security is not a product, but a process. Security tests and audits have to constantly be accomplished. Once a security flaw is detected, a software patch fixing the security weakness could be then produced. This continuous security evaluation, which is iterative, might be expensive. In this paper, a novel vulnerability discovery approach is presented: Hadros. The particularity of the proposed design is that security tests are distributively executed among all the deployed IoT/IIoT nodes and performed at the idle time of the system, while runtime. Hadros is suitable and advantageous for the IoT and IIoT era, due to the fact that testing coverage is broadly increased as more devices are incorporated. Meanwhile, resources employed by the security researchers are also significantly reduced. Jose Luis Flores 0001, Imanol Mugarza |
ETFA | 1 |
| 2007 | Wrapper discretization by means of estimation of distribution algorithms
Jose Luis Flores 0001, Iñaki Inza, Pedro Larrañaga |
Intell. Data Anal. | 1 |