EDBT 2026 Demo / reviewers in the wild / expert
Alejandro Guerra-Manzanares
dblp:242/2584
· DBLP profile ↗
25ranked-venue papers
14as first author
21since 2021 · last 2026
0000-0002-3655-5804ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 9 first-author · 11 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Trust Gap in Agentic Search: How Verbal-Imagery Cognitive Styles Shape Behavioural Signals and AI AcceptanceabstractThe paradigm of web search is currently shifting from reactive information retrieval to Agentic AI, where proactive systems autonomously synthesise information to assist users. However, for these agents to be effective, they must understand which user parameters drive behaviour to resolve the personalisation cold-start problem. While cognitive architecture is a recognised factor, empirical evidence linking specific traits to web search interaction remains unclear. This paper investigates the Verbal-Imagery (V-I) cognitive style dimension and its influence on proactive search behaviour, mental workload (MWL), and overall search user interface (SUI) alignment. Through a controlled user study (N = 20), web search behaviours were evaluated using interaction logs and think-aloud protocols, while MWL and usability were assessed via NASA-TLX and the System Usability Scale (SUS). Our findings reveal that verbalisers and imagers adopt statistically distinct navigational preferences: ver-balisers prefer sporadic, reactive interactions, while imagers rely on structured, proactive synthesis such as the Knowledge Panel. It is worth noting that qualitative data identifies a "trust gap" in AI-generated overviews based on cognitive modality preferences. These results demonstrate that the V-I dimension is a critical parameter for user modelling in agentic systems. We conclude by proposing requirements for user-aware agentic information retrieval, providing a framework for agents to dynamically adapt their representation strategies to minimise cognitive friction and enhance trust in proactive computing environments. This work is licensed under a Creative Commons "Attribution 4.0 International" license. Alejandro Guerra-Manzanares, Boon-Giin Lee, Dave Towey, Max L. Wilson 0001, Matthew Pike |
COMPSAC | 3 |
| 2026 | An Empirical Study of Turbidity Forecasting on Open Aquaponics Sensor Data
Yipeng Xu, Alejandro Guerra-Manzanares, Kwadwo Dompreh, Siegfried K. Yeboah, Matthew Pike |
COMPSAC | 3 |
| 2026 | Enhancing Continual Learning for Software Vulnerability Prediction: Addressing Catastrophic Forgetting via Hybrid‑Confidence‑Aware Selective Replay for Temporal LLM Fine-Tuning
Xuhui Dou, Hayretdin Bahsi, Alejandro Guerra-Manzanares |
ICISSP (1) | 3 |
| 2026 | Exploring Robust Intrusion Detection: A Benchmark Study of Feature Transferability in IoT Botnet Attack Detection
Alejandro Guerra-Manzanares, Jialin Huang |
ICISSP (1) | 1 |
| 2026 | MI²DAS: A Multi-Layer Intrusion Detection Framework with Incremental Learning for Securing Industrial IoT Networks
Wei Lian, Alejandro Guerra-Manzanares |
ICISSP (1) | 2 |
| 2026 | Differential Effects of Virtual and Augmented Reality on Social Presence and Engagement in Collaborative Gaming for Unfamiliar UsersabstractMany studies have shown that collaborative tasks in immersive virtual reality (VR) and augmented reality (AR) environments can enhance collaborative outcomes in learning, training, and game-based contexts. However, the literature offers limited information on how these environments differentially shape social presence and collaborative engagement, particularly among unfamiliar users. This study addresses this gap by examining differences in social presence and collaborative engagement between VR and AR environments for unfamiliar pairs. A between-subjects experiment used an escape room game that featured three collaborative tasks, identically implemented in both VR and AR. The key difference was that the VR experience was stationary, while the AR experience required physical movement between rooms. The study involved 52 participants, divided into VR and AR groups, where two unfamiliar participants were paired into teams to complete the tasks. The results indicate significant differences in collaborative dynamics and user perception between the two environments. Specifically, VR pairs reported a stronger sense of immersion and flow state, whereas AR pairs demonstrated greater contextual awareness and behavioral coordination. Cybersickness measures also differed between conditions; given the locomotion mismatch, this pattern should be interpreted cautiously and not attributed to the environment alone. This finding improves understanding of the impact of immersive environments on collaborative processes and offers insights for designing collaborative XR applications (e.g., training and game-based teamwork), particularly for unfamiliar users. Lijie Zheng, Guoyueyang Cheng, Shaoteng Ke, Jiachen Yuan, Boon-Giin Lee, Matthew Pike, Alejandro Guerra-Manzanares |
VR | 8 |
| 2026 | COCO-QN: An Efficient Content-Aware Congestion Control Mechanism for Maintaining QoS in NDN
Wenzhuo Lyu, Pushpendu Kar, Sherif Welsen, Alejandro Guerra-Manzanares |
IEEE Internet Things J. | 4 |
| 2025 | BlendFL: Blended Federated Learning for Handling Multimodal Data HeterogeneityabstractOne of the key challenges of collaborative machine learning, without data sharing, is multimodal data heterogeneity in real-world settings. While Federated Learning (FL) enables model training across multiple clients, existing frameworks, such as horizontal and vertical FL, are only effective in ‘ideal’ settings that meet specific assumptions. Hence, they struggle to address scenarios where neither all modalities nor all samples are represented across the participating clients. To address this gap, we propose BlendFL, a novel FL framework that seamlessly blends the principles of horizontal and vertical FL in a synchronized and non-restrictive fashion despite the asymmetry across clients. Specifically, any client within BlendFL can benefit from either of the approaches, or both simultaneously, according to its available dataset. In addition, BlendFL features a decentralized inference mechanism, empowering clients to run collaboratively trained local models using available local data, thereby reducing latency and reliance on central servers for inference. We also introduce BlendAvg, an adaptive global model aggregation strategy that prioritizes collaborative model updates based on each client’s performance. We trained and evaluated BlendFL and other state-of-the-art baselines on three classification tasks using a large-scale real-world multimodal medical dataset and a popular multimodal benchmark. Our results highlight BlendFL’s superior performance for both multimodal and unimodal classification. Ablation studies demonstrate BlendFL’s faster convergence compared to traditional approaches, accelerating collaborative learning. Overall, in our study we highlight the potential of BlendFL for handling multimodal data heterogeneity for collaborative learning in real-world settings where data privacy is crucial, such as in healthcare and finance. Alejandro Guerra-Manzanares, Omar El-Herraoui, Michail Maniatakos, Farah Shamout |
IJCNN | 1 |
| 2025 | MILES: Modality-Informed Learning Rate Scheduler for Balancing Multimodal LearningabstractThe aim of multimodal neural networks is to combine diverse data sources, referred to as modalities, to achieve enhanced performance compared to relying on a single modality. However, training of multimodal networks is typically hindered by modality overfitting, where the network relies excessively on one of the available modalities. This often yields sub-optimal performance, hindering the potential of multimodal learning and resulting in marginal improvements relative to unimodal models. In this work, we present the Modality-Informed Learning ratE Scheduler (MILES) for training multimodal joint fusion models in a balanced manner. MILES leverages the differences in modality-wise conditional utilization rates during training to effectively balance multimodal learning. The learning rate is dynamically adjusted during training to balance the speed of learning from each modality by the multimodal model, aiming for enhanced performance in both multimodal and unimodal predictions. We extensively evaluate MILES on four multimodal joint fusion tasks and compare its performance to seven state-of-the-art baselines. Our results show that MILES outperforms all baselines across all tasks and fusion methods considered in our study, effectively balancing modality usage during training. This results in improved multimodal performance and stronger modality encoders, which can be leveraged when dealing with unimodal samples or absent modalities. Overall, our work highlights the impact of balancing multimodal learning on improving model performance. Alejandro Guerra-Manzanares, Farah Shamout |
IJCNN | 1 |
| 2025 | HExNet: Enhancing malware classification through hierarchical CNNs and multi-level feature attributionabstractThe ever-shifting landscape of malware presents a significant threat, as it routinely circumvents traditional defenses. This paper presents HExNet, a Hierarchical Explainable Convolutional Neural Network (CNN) architecture, designed to improve malware analysis and bolster security defenses. Recognizing the growing sophistication of malware, HExNet leverages a dual image representation, converting assembly mnemonics and raw bytecode of malware into visual representations for in-depth pattern recognition. The architecture, optimized for performance and security relevance, integrates multi-level features to enhance detection accuracy. To increase trust and facilitate security audits, HExNet incorporates SHAPley Additive Explanations (SHAP), Class Activation Maps (CAM), and GIST descriptors, providing transparent insights into the model’s classification process. t-SNE visualizations further demonstrate HExNet’s ability to effectively separate malware families, aiding in security intelligence. Evaluated on the Microsoft Malware Classification Challenge (BIG 2015) dataset, HExNet achieves an overall F1-score of 0.9890, with three malware families reaching a perfect F1-score of 1.0 and the remaining six families achieving near-optimal values. To evaluate the generalization capability, we further tested HExNet on a custom dataset consisting 26,401 samples collected from VirusShare, where the proposed model achieved an F1-score of 0.9724, demonstrating generalization performance across diverse malware datasets. Muhammed Shafi K. P., P. Vinod 0001, Rafidha Rehiman K. A., Alejandro Guerra-Manzanares |
J. Inf. Secur. Appl. | 4 |
| 2024 | Machine Learning for Android Malware Detection: Mission Accomplished? A Comprehensive Review of Open Challenges and Future PerspectivesabstractThe vast body of machine learning based Android malware detection research, reporting high-performance metrics using a wide variety of proposed solutions, enables the logical derivation of the (mis)conception of being a problem solved and, therefore, losing its appeal as a field of research. However, after surveying and scrutinizing the related literature, this deceptive deduction is debunked. In this paper, we identify five significant unresolved challenges neglected by the specialized research that prevent the qualification of Android malware detection as a problem solved. From methodological flaws to invalid postulates and data set limitations, these challenges, which are thoroughly described throughout the paper, hamper effective, long-term machine learning based Android malware detection. This comprehensive review of the state-of-the-art highlights and motivates future research directions in the Android malware detection domain that may bring the problem closer to being solved. Alejandro Guerra-Manzanares |
Comput. Secur. | 1 |
| 2024 | Stream clustering guided supervised learning for classifying NIDS alerts
Risto Vaarandi, Alejandro Guerra-Manzanares |
Future Gener. Comput. Syst. | 2 |
| 2024 | Network IDS alert classification with active learning techniques
Risto Vaarandi, Alejandro Guerra-Manzanares |
J. Inf. Secur. Appl. | 2 |
| 2024 | Multimodal Machine Learning for Stroke Prognosis and Diagnosis: A Systematic ReviewabstractStroke is a life-threatening medical condition that could lead to mortality or significant sensorimotor deficits. Various machine learning techniques have been successfully used to detect and predict stroke-related outcomes. Considering the diversity in the type of clinical modalities involved during management of patients with stroke, such as medical images, bio-signals, and clinical data, multimodal machine learning has become increasingly popular. Thus, we conducted a systematic literature review to understand the current status of state-of-the-art multimodal machine learning methods for stroke prognosis and diagnosis. Following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines during literature search and selection, our results show that the most dominant techniques are related to the fusion paradigm, specifically early, joint and late fusion. We discuss opportunities to leverage other multimodal learning paradigms, such as multimodal translation and alignment, which are generally less explored. We also discuss the scale of datasets and types of modalities used to develop existing models, highlighting opportunities for the creation of more diverse multimodal datasets. Finally, we present ongoing challenges and provide a set of recommendations to drive the next generation of multimodal learning methods for improved prognosis and diagnosis of patients with stroke. Saeed Shurrab, Alejandro Guerra-Manzanares, Amani Magid, Bartlomiej Piechowski-Jozwiak, Seyed Farokh Atashzar, Farah Shamout |
IEEE J. Biomed. Health Informatics | 2 |
| 2023 | Corrigendum to Concept drift and cross-device behavior: Challenges and implications for effective android malware detection Computers & Security, Volume 120, 102757
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi |
Comput. Secur. | 1 |
| 2023 | On the application of active learning for efficient and effective IoT botnet detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi |
Future Gener. Comput. Syst. | 1 |
| 2022 | On the Application of Active Learning to Handle Data Evolution in Android Malware Detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi |
ICDF2C | 1 |
| 2022 | Concept drift and cross-device behavior: Challenges and implications for effective android malware detection
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi |
Comput. Secur. | 1 |
| 2022 | On the relativity of time: Implications and challenges of data drift on long-term effective android malware detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi |
Comput. Secur. | 1 |
| 2022 | Android malware concept drift using system calls: Detection, characterization and challenges
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi |
Expert Syst. Appl. | 1 |
| 2021 | KronoDroid: Time-based Hybrid-featured Dataset for Effective Android Malware Detection and CharacterizationabstractAndroid malware evolution has been neglected by the available data sets, thus providing a static snapshot of a non-stationary phenomenon. The impact of the time variable has not had the deserved attention by the Android malware research, omitting its degenerative impact on the performance of machine learning-based classifiers (i.e., concept drift). Besides, the sources of dynamic data and their particularities have been overlooked (i.e., real devices and emulators). Critical factors to take into account when aiming to build more effective, robust, and long-lasting Android malware detection systems. In this research, different sources of benign and malware data are merged, generating a data set encompassing a larger time frame and 489 static and dynamic features are collected. The particularities of the source of the dynamic features (i.e., system calls) are attended using an emulator and a real device, thus generating two equally featured sub-datasets. The main outcome of this research is a novel, labeled, and hybrid-featured Android dataset that provides timestamps for each data sample, covering all years of Android history, from 2008-2020, and considering the distinct dynamic data sources. The emulator data set is composed of 28,745 malicious apps from 209 malware families and 35,246 benign samples. The real device data set contains 41,382 malware, belonging to 240 malware families, and 36,755 benign apps. Made publicly available as KronoDroid, in a structured format, it is the largest hybrid-featured Android dataset and the only one providing timestamped data, considering dynamic sources’ particularities and including samples from over 209 Android malware families. Alejandro Guerra-Manzanares, Hayretdin Bahsi, Sven Nomm |
Comput. Secur. | 1 |
| 2020 | MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network
Alejandro Guerra-Manzanares, Jorge Medina-Galindo, Hayretdin Bahsi, Sven Nomm |
ICISSP | 1 |
| 2019 | Hybrid Feature Selection Models for Machine Learning Based Botnet Detection in IoT NetworksabstractTimely detection of intrusions is essential in IoT networks, considering the massive attacks launched by the huge-sized botnets which are composed of insecure devices. Machine learning methods have demonstrated promising results for the detection of such attacks. However, the effectiveness of such methods may greatly benefit from the reduction of feature set size as this may prevent the impeding impact of unnecessary features and minimize the computational resources required for intrusion detection in such networks having several limitations. This paper elaborates on feature selection methods applied to machine learning models which are induced for botnet detection in IoT networks. A particular attention is devoted to the use of wrapper methods and their combination with filter methods. While filter-based feature selection methods provide a computationally light approach to select the most informative features, it is shown that their utilization in combination with wrapper methods boosts up the detection accuracy. Alejandro Guerra-Manzanares, Hayretdin Bahsi, Sven Nomm |
CW | 1 |
| 2019 | In-depth Feature Selection and Ranking for Automated Detection of Mobile MalwareabstractNew malware detection techniques are highly needed due to the increasing threat posed by mobile malware. Machine learning techniques have provided promising results in this problem domain. However, feature selection, which is an essential instrument to overcome the curse of dimensionality, presenting higher interpretable results and optimizing the utilization of computational resources, requires more attention in order to induce better learning models for mobile malware detection. In this paper, in order to find out the minimum feature set that provides higher accuracy and analyze the discriminatory powers of different features, we employed feature selection and ranking methods to datasets characterized by system calls and permissions. These features were extracted from malware application samples belonging to two different time-frames (2010-2012 and 2017-2018) and benign applications. We demonstrated that selected feature sets with small sizes, in both feature categories, are able to provide high accuracy results. However, we identified a decline in the discriminatory power of the selected features in both categories when the dataset is induced by the recent malware samples instead of old ones, indicating a concept drift. Although we plan to model the concept drift in our
future studies, the feature selection results presented in this study give a valuable insight regarding the change occurred in the best discriminating features during the evolvement of mobile malware over time. Alejandro Guerra-Manzanares, Sven Nomm, Hayretdin Bahsi |
ICISSP | 1 |
| 2019 | Towards the Integration of a Post-Hoc Interpretation Step into the Machine Learning Workflow for IoT Botnet DetectionabstractThe analysis of the interplay between the feature selection and the post-hoc local interpretation steps in a machine learning workflow followed for IoT botnet detection constitutes the research scope of the present paper. While the application of machine learning-based techniques has become a trend in cyber security, the main focus has been almost on detection accuracy. However, providing the relevant explanation for a detection decision is a vital requirement in a tiered incident handling processes of the contemporary security operations centers. Moreover, the design of intrusion detection systems in IoT networks has to take the limitations of the computational resources into consideration. Therefore, resource limitations in addition to human element of incident handling necessitate considering feature selection and interpretability at the same time in machine learning workflows. In this paper, first, we analyzed the selection of features and its implication on the data accuracy. Second, we investigated the impact of feature selection on the explanations generated at the post-hoc interpretation phase. We utilized a filter method, Fisher's Score and Local Interpretable Model-Agnostic Explanation (LIME) at feature selection and post-hoc interpretation phases, respectively. To evaluate the quality of explanations, we proposed a metric that reflects the need of the security analysts. It is demonstrated that the application of both steps for the particular case of IoT botnet detection may result in highly accurate and interpretable learning models induced by fewer features. Our metric enables us to evaluate the detection accuracy and interpretability in an integrated way. Sven Nomm, Alejandro Guerra-Manzanares, Hayretdin Bahsi |
ICMLA | 2 |